<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-AU"
                       href="https://www.techradar.com/au/feeds/tag/cybercrime"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar AU in Cybercrime ]]></title>
                <link>https://www.techradar.com/au/computing/computing-security/cybercrime</link>
        <description><![CDATA[ All the latest cybercrime content from the TechRadar  AU team ]]></description>
                                    <lastBuildDate>Thu, 10 Sep 2026 18:55:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-launches-investigation-after-153-million-drivers-licenses-apparently-leaked-on-russian-cybercrime-forum</link>
                                                                            <description>
                            <![CDATA[ Lousiana-based identity verification service IDScan identified as the target of a hack that leaked 153 million US drivers licenses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pJfgMSYGXMyKq5zMKcF2g7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg">
                                                            <media:credit><![CDATA[wigglestick/ Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:description>                                                            <media:text><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:text>
                                <media:title type="plain"><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liquid Network halts new transactions after 'nice guy' hackers steal nearly all its Bitcoin — but then return most of it after a patch is issued ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/liquid-network-halts-new-transactions-after-nice-guy-hackers-steal-nearly-all-its-bitcoin-but-then-return-most-of-it-after-a-patch-is-issued</link>
                                                                            <description>
                            <![CDATA[ Liquid Network is still disrupted, but users can breathe a sigh of relief as most of the stolen funds have been returned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oguXoFVDTGkmgxvQsQBpU3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bitcoin]]></media:description>                                                            <media:text><![CDATA[Bitcoin]]></media:text>
                                <media:title type="plain"><![CDATA[Bitcoin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why did FulcrumSec hackers try to extort Manchester Airports Group, and what happens now the data is leaked? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-did-fulcrumsec-hackers-try-to-extort-manchester-airports-group-and-what-happens-now-the-data-is-leaked-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ After hackers failed to extort Manchester Airports Group and posted the data of nearly 9 million people online, we asked the experts what's really going on. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fRCxPaa9De9wPUPVGxjDbh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 14:57:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only one in five UK CEOs say their cyber insurance will cover the full cost of a cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/only-one-in-five-uk-ceos-say-their-cyber-insurance-will-cover-the-full-cost-of-a-cyberattack</link>
                                                                            <description>
                            <![CDATA[ New data has revealed that only one in five CEOs expect full coverage from their cyber insurance policy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ3r6t6Y6FWyxjoMbJbwM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Manchester Airports hackers just posted the data of 8.7 million people online — failed extortion attempt triggers data dump sale ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The hacker group responsible for the MAG hack has posted the data online</strong></li><li><strong>PII is included within the data, putting victims at risk of targeted phishing and scams</strong></li><li><strong>"MAG is confident that we have taken effective measures to protect our customers"</strong></li></ul><p>The hackers behind the Manchester Airport hack have posted their trove of data on 8.7 million people online after failing to extort the Manchester Airport Group.</p><p>The data stolen during the attack included personally identifiable information (PII) such as email addresses, phone numbers, vehicle registrations and postcodes.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.</p><h2 id="hackers-look-for-money-elsewhere">Hackers look for money elsewhere</h2><p>When hackers successfully breach systems and steal sensitive information, such as customer data, they will attempt to extort the company they stole it from for money. In return, the hackers promise not to release the data. </p><p>FulcrumSec has claimed responsibility for the attack. They tried to extort MAG but the company refused to pay, in line with what governments and cybersecurity agencies are advising. By not paying the hackers, it removes the financial incentive to steal the data in the first place.</p><p>In order to recoup some money from their efforts in hacking MAG, the hackers have now posted the trove of data online in the hopes that another cybercriminal group will pay for access to the information.</p><p>The information contains valuable information that hackers can use to target the victims of the data breach, launching highly specific phishing campaigns. For those affected by the MAG breach, this could include scams that use the email addresses, car registrations and postcodes of victims.</p><p>In the hackers post online, they claim the database is “half a terabyte, and every byte of it is pure PII” (Via <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank" rel="nofollow"><em>BBC</em></a>).</p><p>“Reported exposure of booking history, travel dates, vehicle information, purchase references and customer profiles is a major escalation from what’s already been revealed about the Manchester Airports Group data breach,” said David Sancho, Senior Threat Researcher, TrendAI.</p><p>“This appears to be much more than a simple contact-data breach. The information reportedly exposed is exactly the kind used to craft extremely credible phishing campaigns by referring to information that intended victims would expect only their airport of choice or booking provider to know.”</p><p>“The risk is especially pressing given today’s criminal use of AI to generate highly targeted phishing and social-engineering campaigns at scale. FulcrumSec, the group that’s claimed responsibility for this breach, has previously been reported to use LLMs to analyse stolen data, so that risk is a real one. FulcrumSec is a relatively new but increasingly credible data-extortion group. Seemingly active since late 2025, their campaigns focus on stealing sensitive information and using the threat of disclosure as leverage rather than encrypting systems,” he added.</p><p>“In light of these claims, and following independent verification, MAG companies should update affected customers as quickly as the scope of the breach becomes clearer, because the advice they need may change with it. I would urge customers to be suspicious of messages referring to upcoming trips, parking, Fast Track, lounges, refunds, booking changes or payment problems. They should avoid following links in unsolicited messages and instead access their booking through the official airport or provider website directly.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale</link>
                                                                            <description>
                            <![CDATA[ FulcrumSec attempted to extort Manchester Airports Group, but failed. Now, the cyber-criminals have published the information online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Zo32UDyNL5Yb9Nkfi4KDH8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 15:14:39 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 15:17:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The hacker group responsible for the MAG hack has posted the data online</strong></li><li><strong>PII is included within the data, putting victims at risk of targeted phishing and scams</strong></li><li><strong>"MAG is confident that we have taken effective measures to protect our customers"</strong></li></ul><p>The hackers behind the Manchester Airport hack have posted their trove of data on 8.7 million people online after failing to extort the Manchester Airport Group.</p><p>The data stolen during the attack included personally identifiable information (PII) such as email addresses, phone numbers, vehicle registrations and postcodes.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.</p><h2 id="hackers-look-for-money-elsewhere">Hackers look for money elsewhere</h2><p>When hackers successfully breach systems and steal sensitive information, such as customer data, they will attempt to extort the company they stole it from for money. In return, the hackers promise not to release the data. </p><p>FulcrumSec has claimed responsibility for the attack. They tried to extort MAG but the company refused to pay, in line with what governments and cybersecurity agencies are advising. By not paying the hackers, it removes the financial incentive to steal the data in the first place.</p><p>In order to recoup some money from their efforts in hacking MAG, the hackers have now posted the trove of data online in the hopes that another cybercriminal group will pay for access to the information.</p><p>The information contains valuable information that hackers can use to target the victims of the data breach, launching highly specific phishing campaigns. For those affected by the MAG breach, this could include scams that use the email addresses, car registrations and postcodes of victims.</p><p>In the hackers post online, they claim the database is “half a terabyte, and every byte of it is pure PII” (Via <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank" rel="nofollow"><em>BBC</em></a>).</p><p>“Reported exposure of booking history, travel dates, vehicle information, purchase references and customer profiles is a major escalation from what’s already been revealed about the Manchester Airports Group data breach,” said David Sancho, Senior Threat Researcher, TrendAI.</p><p>“This appears to be much more than a simple contact-data breach. The information reportedly exposed is exactly the kind used to craft extremely credible phishing campaigns by referring to information that intended victims would expect only their airport of choice or booking provider to know.”</p><p>“The risk is especially pressing given today’s criminal use of AI to generate highly targeted phishing and social-engineering campaigns at scale. FulcrumSec, the group that’s claimed responsibility for this breach, has previously been reported to use LLMs to analyse stolen data, so that risk is a real one. FulcrumSec is a relatively new but increasingly credible data-extortion group. Seemingly active since late 2025, their campaigns focus on stealing sensitive information and using the threat of disclosure as leverage rather than encrypting systems,” he added.</p><p>“In light of these claims, and following independent verification, MAG companies should update affected customers as quickly as the scope of the breach becomes clearer, because the advice they need may change with it. I would urge customers to be suspicious of messages referring to upcoming trips, parking, Fast Track, lounges, refunds, booking changes or payment problems. They should avoid following links in unsolicited messages and instead access their booking through the official airport or provider website directly.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US says Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate, and more ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Multiple US agencies and departments were breached by Chinese state-sponsored hackers</strong></li><li><strong>The hackers use a massive botnet of compromised IoT devices to obscure the origin of their traffic</strong></li><li><strong>The hackers breached computers belonging to NASA, the Federal Reserve, the Senate, the Department of Justice, and more</strong></li></ul><p>As part of a disclosure into the Justice Department and FBI operations to prevent Chinese threat actors from accessing a malicious botnet and hacking platforms, the US Office of Public Affairs has revealed that the hackers managed to breach computers belonging to multiple US government departments.</p><p>The <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank" rel="nofollow">disclosure</a> said the victims of “computer intrusion” included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the US Senate.</p><p>The Chinese hackers created a platform that provides paid-for hacking services on behalf of its customers. The two services, QScan and QTRouter, detect and infect internet-connected devices to use as part of a proxy network that obscures the origins of internet traffic, allowing Chinese hackers to slip into networks without detection.</p><div class="product"><a data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="us-seizes-hacking-domains-to-prevent-access">US seizes hacking domains to prevent access</h2><p>The Chinese state-sponsored hacking group the Justice Department and FBI have disrupted is named in court documents - unsealed by the Southern District of California - as “QTFY”.</p><p>QTFY was apparently hired by the Nanjing Xinjiuwei Network Technology Company, to create and operate the QScan and QTRouter operations, while using both systems to infiltrate US critical infrastructure.</p><p>“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. </p><p>“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking - and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”</p><p>The authorization to disrupt the operation of QTFY comes as part of a range of technical operations designed to disrupt the ability of the People’s Republic of China to launch hacking activities on US government systems and critical infrastructure</p><p>Previous operations include the removal of the <a href="https://www.techradar.com/pro/security/millions-of-devices-still-connect-to-this-dangerous-malware-despite-the-creators-ditching-it-years-ago">PlugX malware</a> from thousands of US computers, alongside operations to disrupt Chinese botnets leveraging millions of unsecured IoT devices.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-says-chinese-hackers-broke-into-justice-department-nasa-federal-reserve-senate-and-more</link>
                                                                            <description>
                            <![CDATA[ Chinese state-sponsored hackers breached multiple US agencies and departments using a botnet to obscure their traffic. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bMvoYvhsb985ZxCY4jsFVE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 01:15:00 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 10:44:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Multiple US agencies and departments were breached by Chinese state-sponsored hackers</strong></li><li><strong>The hackers use a massive botnet of compromised IoT devices to obscure the origin of their traffic</strong></li><li><strong>The hackers breached computers belonging to NASA, the Federal Reserve, the Senate, the Department of Justice, and more</strong></li></ul><p>As part of a disclosure into the Justice Department and FBI operations to prevent Chinese threat actors from accessing a malicious botnet and hacking platforms, the US Office of Public Affairs has revealed that the hackers managed to breach computers belonging to multiple US government departments.</p><p>The <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank" rel="nofollow">disclosure</a> said the victims of “computer intrusion” included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the US Senate.</p><p>The Chinese hackers created a platform that provides paid-for hacking services on behalf of its customers. The two services, QScan and QTRouter, detect and infect internet-connected devices to use as part of a proxy network that obscures the origins of internet traffic, allowing Chinese hackers to slip into networks without detection.</p><div class="product"><a data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="us-seizes-hacking-domains-to-prevent-access">US seizes hacking domains to prevent access</h2><p>The Chinese state-sponsored hacking group the Justice Department and FBI have disrupted is named in court documents - unsealed by the Southern District of California - as “QTFY”.</p><p>QTFY was apparently hired by the Nanjing Xinjiuwei Network Technology Company, to create and operate the QScan and QTRouter operations, while using both systems to infiltrate US critical infrastructure.</p><p>“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. </p><p>“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking - and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”</p><p>The authorization to disrupt the operation of QTFY comes as part of a range of technical operations designed to disrupt the ability of the People’s Republic of China to launch hacking activities on US government systems and critical infrastructure</p><p>Previous operations include the removal of the <a href="https://www.techradar.com/pro/security/millions-of-devices-still-connect-to-this-dangerous-malware-despite-the-creators-ditching-it-years-ago">PlugX malware</a> from thousands of US computers, alongside operations to disrupt Chinese botnets leveraging millions of unsecured IoT devices.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security expert hijacks Apple's Find My network to share data with a Linux device ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware</strong></li><li><strong>The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users</strong></li><li><strong>The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed</strong></li></ul><p>Apple keeps the full <a href="https://www.techradar.com/how-to/how-to-use-find-my" target="_blank">Find My experience</a> locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.</p><p>A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as iPhones and iPads.</p><p>Find My, Apple's catch-all tool for locating hardware such as AirTags, iPhones, and iPads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.</p><h2 id="an-interesting-trick-that-still-requires-consent-to-get-the-job-done">An interesting trick that still requires consent to get the job done</h2><p>The task is not an easy one to begin with: convincing Apple's back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information shared via the Find My platform required a lot of trial and error to get going.</p><p>It is important to clarify here that Apple's system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.</p><p>Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple's private language to query its servers and process the information it received.</p><p>It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple's internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.</p><p>Once done, a Linux box with a signed certificate could sign its own requests and register as a Find My device, but it still had to subscribe to six different subservices to function. The registration request also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup.</p><p>The researcher then issued a SubscribeAndFetch request that provided an encrypted location key from his friend's Apple device to the Linux box, masquerading as one.</p><p>What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn't require a jailbreak, a leaked key, <a href="https://www.techradar.com/computing/laptops/macbooks" target="_blank">or even a Mac</a> to do the job. Instead, open-source clients and decompiled daemons were the norm, with a trial-and-error approach that eventually paid off.</p><p>The technique has its limitations: attacks can not target a stranger, and consent is required to track even one's friends. It shows that Apple's boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.</p><p>Apple has <a href="https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496" target="_blank">yet to respond to media queries</a> about whether it plans to address the demonstrated trick or patch the loop in the near future.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/security-expert-hijacks-apples-find-my-network-to-share-data-with-a-linux-device</link>
                                                                            <description>
                            <![CDATA[ Researcher tricks Apple's Find My into feeding live location data to a Linux box, with no Mac or iPhone required. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7TM6znSKzek3xXArrwGW4S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-1280-80.jpg">
                                                            <media:credit><![CDATA[Future / Axel Metz]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Apple&amp;#39;s Find My iPhone displayed in settings]]></media:description>                                                            <media:text><![CDATA[Find My iPhone displayed in settings]]></media:text>
                                <media:title type="plain"><![CDATA[Find My iPhone displayed in settings]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware</strong></li><li><strong>The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users</strong></li><li><strong>The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed</strong></li></ul><p>Apple keeps the full <a href="https://www.techradar.com/how-to/how-to-use-find-my" target="_blank">Find My experience</a> locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.</p><p>A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as iPhones and iPads.</p><p>Find My, Apple's catch-all tool for locating hardware such as AirTags, iPhones, and iPads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.</p><h2 id="an-interesting-trick-that-still-requires-consent-to-get-the-job-done">An interesting trick that still requires consent to get the job done</h2><p>The task is not an easy one to begin with: convincing Apple's back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information shared via the Find My platform required a lot of trial and error to get going.</p><p>It is important to clarify here that Apple's system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.</p><p>Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple's private language to query its servers and process the information it received.</p><p>It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple's internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.</p><p>Once done, a Linux box with a signed certificate could sign its own requests and register as a Find My device, but it still had to subscribe to six different subservices to function. The registration request also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup.</p><p>The researcher then issued a SubscribeAndFetch request that provided an encrypted location key from his friend's Apple device to the Linux box, masquerading as one.</p><p>What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn't require a jailbreak, a leaked key, <a href="https://www.techradar.com/computing/laptops/macbooks" target="_blank">or even a Mac</a> to do the job. Instead, open-source clients and decompiled daemons were the norm, with a trial-and-error approach that eventually paid off.</p><p>The technique has its limitations: attacks can not target a stranger, and consent is required to track even one's friends. It shows that Apple's boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.</p><p>Apple has <a href="https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496" target="_blank">yet to respond to media queries</a> about whether it plans to address the demonstrated trick or patch the loop in the near future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Of course this fake GTA 6 ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GTA 6 leak hunters now face fake downloads designed to compromise their computers</strong></li><li><strong>The suspicious ISO reportedly disables Windows security tools after execution on affected systems</strong></li><li><strong>A tiny 50KB payload allegedly sits inside a gigantic 113GB file</strong></li></ul><p>Keen <a href="https://www.techradar.com/gaming/grand-theft-auto-6-delayed-again-but-itll-still-ship-in-2026">Grand Theft Auto 6</a> fans searching for leaked copies now face another risk: a huge ISO file is reportedly circulating across torrent sites.</p><p>The file is said to measure 113GB, yet online testers claim almost all that space consists of empty data rather than genuine game assets.</p><p>Their analysis reportedly found a small malicious program hidden inside the file, making the download appear far more dangerous than it normally would.</p><h2 id="the-huge-size-made-it-feel-genuine">The huge size made it feel genuine</h2><p>The suspicious file reportedly began circulating on torrent sites after renewed interest in leaked GTA 6material and claims of a complete game build.</p><p>However, testers who examined the ISO reportedly found that it contains 99.99% empty zeroes, leaving only about 50KB of data identified as malicious code.</p><p>“I did some reverse engineering and confirmed that it is fully fake and full of viruses,” said @Aidas29506493, an online researcher on X.</p><p>The 113GB figure was created to make the file resemble a legitimate game release while concealing a much smaller payload, which could be <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Yet file size alone provides no evidence that an alleged copy contains authentic game assets or executable code from Rockstar.</p><p>The alleged code reportedly includes commands designed to weaken Windows Defender and interfere with other security tools on affected computers.</p><p>Such behaviour would allow the <a href="https://www.techradar.com/best/best-malware-removal">malware</a> to operate with fewer protections after someone launches the downloaded file on Windows.</p><p>The analysis also reportedly found a PowerShell command that adds the system drive to Windows Defender's exclusion list for scanning.</p><p>Another command was said to terminate security software, although independent verification of those findings remains limited at this time.</p><h2 id="malware-risk-rises-alongside-gta-6-leak-interest">Malware risk rises alongside GTA 6 leak interest</h2><p>The alleged ISO follows a series of GTA 6 leak claims that have generated substantial interest across gaming communities online.</p><p>A leaker known as Cyberleek has reportedly shared gameplay material and the game's fictional Leonidas map, while demanding changes from Rockstar.</p><p>Take-Two Interactive has also sought information from Microsoft that could help identify users connected with three Discord servers reportedly linked to leaks.</p><p>Those developments have increased attention around unofficial GTA 6 files, creating conditions that criminals can exploit with convincing fake downloads.</p><p>This situation also shows why unreleased game files can carry greater security risks than ordinary pirated software already available publicly.</p><p>Gamers downloading such files may expose <a href="https://www.techradar.com/best/password-generator">passwords</a>, personal files, browser data, or other information if malicious code gains access without warning.</p><p>Rockstar has scheduled the official release of Grand Theft Auto 6 for November 2026, giving players a legitimate alternative to unofficial copies elsewhere.</p><p>Until then, claims surrounding leaked builds and supposed ISOs should be treated cautiously because the files cannot be independently verified as genuine.</p><p>This case provides a strong warning, but further independent testing would be needed to establish every technical claim about the file itself.</p><p>Via <a href="https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded" target="_blank" rel="nofollow">Toms Hardware</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/of-course-this-fake-gta-vi-iso-download-is-malware-testers-reveal-113gb-download-is-99-99-empty-zeroes-with-a-tiny-virus-attached</link>
                                                                            <description>
                            <![CDATA[ A fake 113GB GTA 6 ISO reportedly contains 99.99% empty data and a 50KB malicious payload capable of weakening Windows security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3FAd87SYyFSWBoKcYwevg8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ScNA7GtpLy8tqFJYau6JCL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 20:25:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 10:48:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ScNA7GtpLy8tqFJYau6JCL-1280-80.jpg">
                                                            <media:credit><![CDATA[Sony / Rockstar ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA 6 still from the &#039;It Happens On PS5&#039; ad]]></media:description>                                                            <media:text><![CDATA[GTA 6 still from the &#039;It Happens On PS5&#039; ad]]></media:text>
                                <media:title type="plain"><![CDATA[GTA 6 still from the &#039;It Happens On PS5&#039; ad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ScNA7GtpLy8tqFJYau6JCL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GTA 6 leak hunters now face fake downloads designed to compromise their computers</strong></li><li><strong>The suspicious ISO reportedly disables Windows security tools after execution on affected systems</strong></li><li><strong>A tiny 50KB payload allegedly sits inside a gigantic 113GB file</strong></li></ul><p>Keen <a href="https://www.techradar.com/gaming/grand-theft-auto-6-delayed-again-but-itll-still-ship-in-2026">Grand Theft Auto 6</a> fans searching for leaked copies now face another risk: a huge ISO file is reportedly circulating across torrent sites.</p><p>The file is said to measure 113GB, yet online testers claim almost all that space consists of empty data rather than genuine game assets.</p><p>Their analysis reportedly found a small malicious program hidden inside the file, making the download appear far more dangerous than it normally would.</p><h2 id="the-huge-size-made-it-feel-genuine">The huge size made it feel genuine</h2><p>The suspicious file reportedly began circulating on torrent sites after renewed interest in leaked GTA 6material and claims of a complete game build.</p><p>However, testers who examined the ISO reportedly found that it contains 99.99% empty zeroes, leaving only about 50KB of data identified as malicious code.</p><p>“I did some reverse engineering and confirmed that it is fully fake and full of viruses,” said @Aidas29506493, an online researcher on X.</p><p>The 113GB figure was created to make the file resemble a legitimate game release while concealing a much smaller payload, which could be <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Yet file size alone provides no evidence that an alleged copy contains authentic game assets or executable code from Rockstar.</p><p>The alleged code reportedly includes commands designed to weaken Windows Defender and interfere with other security tools on affected computers.</p><p>Such behaviour would allow the <a href="https://www.techradar.com/best/best-malware-removal">malware</a> to operate with fewer protections after someone launches the downloaded file on Windows.</p><p>The analysis also reportedly found a PowerShell command that adds the system drive to Windows Defender's exclusion list for scanning.</p><p>Another command was said to terminate security software, although independent verification of those findings remains limited at this time.</p><h2 id="malware-risk-rises-alongside-gta-6-leak-interest">Malware risk rises alongside GTA 6 leak interest</h2><p>The alleged ISO follows a series of GTA 6 leak claims that have generated substantial interest across gaming communities online.</p><p>A leaker known as Cyberleek has reportedly shared gameplay material and the game's fictional Leonidas map, while demanding changes from Rockstar.</p><p>Take-Two Interactive has also sought information from Microsoft that could help identify users connected with three Discord servers reportedly linked to leaks.</p><p>Those developments have increased attention around unofficial GTA 6 files, creating conditions that criminals can exploit with convincing fake downloads.</p><p>This situation also shows why unreleased game files can carry greater security risks than ordinary pirated software already available publicly.</p><p>Gamers downloading such files may expose <a href="https://www.techradar.com/best/password-generator">passwords</a>, personal files, browser data, or other information if malicious code gains access without warning.</p><p>Rockstar has scheduled the official release of Grand Theft Auto 6 for November 2026, giving players a legitimate alternative to unofficial copies elsewhere.</p><p>Until then, claims surrounding leaked builds and supposed ISOs should be treated cautiously because the files cannot be independently verified as genuine.</p><p>This case provides a strong warning, but further independent testing would be needed to establish every technical claim about the file itself.</p><p>Via <a href="https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded" target="_blank" rel="nofollow">Toms Hardware</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers exploited trusted software updates to deliver malware directly into car head units</strong></li><li><strong>Kaspersky says this is the first campaign tailored specifically for vehicle head units</strong></li><li><strong>The malware can run silently without showing drivers any visible interface</strong></li></ul><p>Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.</p><p>A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.</p><p>According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.</p><h2 id="compromised-update-channels-deliver-malware-straight-into-vehicles">Compromised update channels deliver malware straight into vehicles</h2><p>Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.</p><p>The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.</p><p>Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.</p><p>Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.</p><p>Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.</p><p>The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.</p><p>Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.</p><p>The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.</p><p>BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.</p><p>Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.</p><p>According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.</p><h2 id="head-units-present-a-growing-and-largely-unprotected-attack-surface">Head units present a growing and largely unprotected attack surface</h2><p>Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.</p><p>Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.</p><p>This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.</p><p>Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.</p><p>However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.</p><p>That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.</p><p>The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/even-connected-car-head-units-are-being-targeted-by-hackers-now-experts-warn-in-car-systems-are-at-risk-of-being-hijacked-into-a-botnet</link>
                                                                            <description>
                            <![CDATA[ Kaspersky discovers Android malware targeting car head units through compromised updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m2NVLV93FhaPCF5tsL4x7Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 18:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg">
                                                            <media:credit><![CDATA[Spotify]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spotify Car Thing]]></media:description>                                                            <media:text><![CDATA[Spotify Car Thing]]></media:text>
                                <media:title type="plain"><![CDATA[Spotify Car Thing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers exploited trusted software updates to deliver malware directly into car head units</strong></li><li><strong>Kaspersky says this is the first campaign tailored specifically for vehicle head units</strong></li><li><strong>The malware can run silently without showing drivers any visible interface</strong></li></ul><p>Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.</p><p>A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.</p><p>According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.</p><h2 id="compromised-update-channels-deliver-malware-straight-into-vehicles">Compromised update channels deliver malware straight into vehicles</h2><p>Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.</p><p>The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.</p><p>Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.</p><p>Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.</p><p>Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.</p><p>The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.</p><p>Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.</p><p>The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.</p><p>BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.</p><p>Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.</p><p>According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.</p><h2 id="head-units-present-a-growing-and-largely-unprotected-attack-surface">Head units present a growing and largely unprotected attack surface</h2><p>Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.</p><p>Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.</p><p>This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.</p><p>Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.</p><p>However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.</p><p>That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.</p><p>The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>With the 2026-27 season kicking off this weekend, Premier League football teams are facing a new set of rules. But these ones aren’t enforced on the pitch, they’re being enforced by the Premier League board.</p><p>As the Premier League has adapted to a new era of fan engagement and interaction, teams are holding huge amounts of personal data, including names, email addresses, credentials, and even financial information. These place them at greater risk of data leaks and make them a primary target for cyber attacks.</p><p>In order to ensure teams take the necessary steps to protect both their data and the data of their fans, the board can impose fines of up to £100,000 for teams that don’t meet the requirements across backups, incident response, risk management, security assurance and much more.</p><div class="product"><a data-dimension112="a2e9fa6a-a129-11f1-998d-59119ff45231" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="a2e9fa6a-a129-11f1-998d-59119ff45231" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="a2e9fa6a-a129-11f1-998d-59119ff45231" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="what-do-the-new-rules-mean-for-premier-league-teams">What do the new rules mean for Premier League teams?</h2><p>The teams previously had to align with a non-prescriptive security baseline issued in 2024, but the new rules place requirements on teams with deadlines for their implementation.</p><p>If these deadlines are not met, the teams can be subject to the aforementioned fine, or referred to an independent commission.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The teams will be required to meet the first set of requirements by April 30, 2027, with further requirements to be met in April 2028 and April 2029. The teams will also have to assess their own compliance by January 10 each year, with a final assessment and evidence submitted to the Premier League board by April 30.</p><p>The board can also request additional detail and evidence where needed to track a team’s progress in adhering to the new rules. If a team does not meet requirements during the interim stage it must submit a plan on how it aims to become compliant within 28 days.</p><h3 class="article-body__section" id="section-expert-perspectives-on-premier-league-cybersecurity-rules"><span>Expert perspectives on Premier League cybersecurity rules</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>The Premier League introducing mandatory cybersecurity standards is the right move, but the detail is where the questions start. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</em></p><p><em>The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment. Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.</em></p><div><blockquote><p>£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</p></blockquote></div><p><em>That said, the direction is unambiguously right. Moving from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions is a meaningful structural shift.</em></p><p><em>Backups, incident response, risk management, and recovery testing are exactly the right foundations. The Premier League doing this proactively rather than reactively before a major breach forces the issue deserves genuine credit.</em></p><p><em>Most governing bodies wait for the headline incident. This one didn’t. The real test is enforcement appetite. Rules without credible consequences change nothing.</em></p><ul><li><strong>Jamie Akhtar, CEO and Co-founder, CyberSmart:</strong></li></ul><p><em>This is an important shift for the Premier League. Cyber security is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.</em></p><p><em>Football clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations. Making areas such as backups, incident response, risk management and security assurance mandatory reflects the reality that a serious cyber incident can quickly become an operational, financial and reputational crisis.</em></p><div><blockquote><p>For clubs, compliance should not become an annual box-ticking exercise.</p></blockquote></div><p><em>For clubs, compliance should not become an annual box-ticking exercise. They need clear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers.</em></p><p><em>Just as importantly, clubs should continuously collect evidence that these controls are operating effectively. The organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.</em></p><ul><li><strong>Anna Collard, SVP of Content Strategy and CISO Advisor, KnowBe4:</strong></li></ul><p><em>Good to see the Premier League treating cybersecurity as a governance issue rather than an IT afterthought. Mandatory rules with real financial consequences (fines of up to £100,000) send the right signal: boards are expected to own this risk, not just delegate it.</em></p><div><blockquote><p>As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</p></blockquote></div><p><em>But fines only address one side of the equation. As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</em></p><p><em>A rushed transfer payment, a fan chasing tickets, an official acting on a "verified" WhatsApp message from someone posing as a coach or chairperson, these are moments of heightened emotion and time pressure, exactly when human judgment degrades. That's not a firewall problem.</em></p><p><em>It's worth remembering that one of the most costly incidents in this sector involved a Premier League club being spear-phished during a £1 million transfer negotiation. That wasn't a technical breach, but a person deceived at a moment of pressure.</em></p><p><em>Rules with teeth are a welcome start. But real resilience means pairing compliance with genuine behavioural readiness, for example helping people recognise urgency as a red flag, not a reason to skip verification.</em></p><ul><li><strong>Cian Heasley, Principal Consultant, Acumen Cyber:</strong></li></ul><p><em>I think it’s a positive step forward. Football clubs are attractive targets because they hold large volumes of sensitive data, process significant financial transactions and rely on operational systems where disruption can have very real consequences. Moving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action.</em></p><p><em>Requiring clubs to have a clear plan, aligned to defined standards and delivered within a set timeframe, also gives them something measurable to work towards. The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</em></p><div><blockquote><p>The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</p></blockquote></div><p><em>The focus on backups, incident response and recovery is particularly important. Preventing every incident simply isn’t realistic, so clubs need to prove they can recover quickly when something does happen. If clubs are working towards common standards, there is also a real opportunity to share lessons around what works, where implementation falls short and how security can continue to improve across the league.</em></p><p><em>In November ‘24, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group, which exfiltrated sensitive data. After the club declined to meet the ransom demand, the ransomware gang published the full dataset on the dark web. The leaked material reportedly included player and sponsor information, and the attackers went as far as invoking GDPR exposure to pressure the club into paying, a tactic that turns a club's own regulatory obligations into leverage. </em></p><p><em>More recently, Dutch club Ajax was named among the organisations affected by the CEVA Logistics breach, where customer data was exposed through a shared shipping vendor rather than a direct compromise, underlining that supply-chain exposure is also as material a risk as any attack on a club's own estate.</em></p><p><em>Taken together, these incidents show why these rules were needed then, though they are pitched as proactive, they must also be driven by these football-related breaches.</em></p><p><em>The £100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed. The Bologna case in particular demonstrates that ransomware leaks can be damaging, which makes resilience and data minimisation far more important than any assumption that a club can negotiate its way out of trouble.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-the-premier-league-now-subject-to-new-cybersecurity-rules-and-what-punishments-could-they-face-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ The Premier League wants to harden teams against emerging cyber threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">26EmiWVfrhDPsZopFsAuC8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u9DTfPvgBEBWg7ADPmTJRF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 23 Aug 2026 09:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 08:39:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u9DTfPvgBEBWg7ADPmTJRF-1280-80.jpg">
                                                            <media:credit><![CDATA[Visionhaus/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close-up of the official Premier League match ball.]]></media:description>                                                            <media:text><![CDATA[A close-up of the official Premier League match ball.]]></media:text>
                                <media:title type="plain"><![CDATA[A close-up of the official Premier League match ball.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u9DTfPvgBEBWg7ADPmTJRF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the 2026-27 season kicking off this weekend, Premier League football teams are facing a new set of rules. But these ones aren’t enforced on the pitch, they’re being enforced by the Premier League board.</p><p>As the Premier League has adapted to a new era of fan engagement and interaction, teams are holding huge amounts of personal data, including names, email addresses, credentials, and even financial information. These place them at greater risk of data leaks and make them a primary target for cyber attacks.</p><p>In order to ensure teams take the necessary steps to protect both their data and the data of their fans, the board can impose fines of up to £100,000 for teams that don’t meet the requirements across backups, incident response, risk management, security assurance and much more.</p><div class="product"><a data-dimension112="a2e9fa6a-a129-11f1-998d-59119ff45231" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="a2e9fa6a-a129-11f1-998d-59119ff45231" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="a2e9fa6a-a129-11f1-998d-59119ff45231" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="what-do-the-new-rules-mean-for-premier-league-teams">What do the new rules mean for Premier League teams?</h2><p>The teams previously had to align with a non-prescriptive security baseline issued in 2024, but the new rules place requirements on teams with deadlines for their implementation.</p><p>If these deadlines are not met, the teams can be subject to the aforementioned fine, or referred to an independent commission.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The teams will be required to meet the first set of requirements by April 30, 2027, with further requirements to be met in April 2028 and April 2029. The teams will also have to assess their own compliance by January 10 each year, with a final assessment and evidence submitted to the Premier League board by April 30.</p><p>The board can also request additional detail and evidence where needed to track a team’s progress in adhering to the new rules. If a team does not meet requirements during the interim stage it must submit a plan on how it aims to become compliant within 28 days.</p><h3 class="article-body__section" id="section-expert-perspectives-on-premier-league-cybersecurity-rules"><span>Expert perspectives on Premier League cybersecurity rules</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>The Premier League introducing mandatory cybersecurity standards is the right move, but the detail is where the questions start. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</em></p><p><em>The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment. Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.</em></p><div><blockquote><p>£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</p></blockquote></div><p><em>That said, the direction is unambiguously right. Moving from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions is a meaningful structural shift.</em></p><p><em>Backups, incident response, risk management, and recovery testing are exactly the right foundations. The Premier League doing this proactively rather than reactively before a major breach forces the issue deserves genuine credit.</em></p><p><em>Most governing bodies wait for the headline incident. This one didn’t. The real test is enforcement appetite. Rules without credible consequences change nothing.</em></p><ul><li><strong>Jamie Akhtar, CEO and Co-founder, CyberSmart:</strong></li></ul><p><em>This is an important shift for the Premier League. Cyber security is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.</em></p><p><em>Football clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations. Making areas such as backups, incident response, risk management and security assurance mandatory reflects the reality that a serious cyber incident can quickly become an operational, financial and reputational crisis.</em></p><div><blockquote><p>For clubs, compliance should not become an annual box-ticking exercise.</p></blockquote></div><p><em>For clubs, compliance should not become an annual box-ticking exercise. They need clear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers.</em></p><p><em>Just as importantly, clubs should continuously collect evidence that these controls are operating effectively. The organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.</em></p><ul><li><strong>Anna Collard, SVP of Content Strategy and CISO Advisor, KnowBe4:</strong></li></ul><p><em>Good to see the Premier League treating cybersecurity as a governance issue rather than an IT afterthought. Mandatory rules with real financial consequences (fines of up to £100,000) send the right signal: boards are expected to own this risk, not just delegate it.</em></p><div><blockquote><p>As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</p></blockquote></div><p><em>But fines only address one side of the equation. As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</em></p><p><em>A rushed transfer payment, a fan chasing tickets, an official acting on a "verified" WhatsApp message from someone posing as a coach or chairperson, these are moments of heightened emotion and time pressure, exactly when human judgment degrades. That's not a firewall problem.</em></p><p><em>It's worth remembering that one of the most costly incidents in this sector involved a Premier League club being spear-phished during a £1 million transfer negotiation. That wasn't a technical breach, but a person deceived at a moment of pressure.</em></p><p><em>Rules with teeth are a welcome start. But real resilience means pairing compliance with genuine behavioural readiness, for example helping people recognise urgency as a red flag, not a reason to skip verification.</em></p><ul><li><strong>Cian Heasley, Principal Consultant, Acumen Cyber:</strong></li></ul><p><em>I think it’s a positive step forward. Football clubs are attractive targets because they hold large volumes of sensitive data, process significant financial transactions and rely on operational systems where disruption can have very real consequences. Moving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action.</em></p><p><em>Requiring clubs to have a clear plan, aligned to defined standards and delivered within a set timeframe, also gives them something measurable to work towards. The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</em></p><div><blockquote><p>The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</p></blockquote></div><p><em>The focus on backups, incident response and recovery is particularly important. Preventing every incident simply isn’t realistic, so clubs need to prove they can recover quickly when something does happen. If clubs are working towards common standards, there is also a real opportunity to share lessons around what works, where implementation falls short and how security can continue to improve across the league.</em></p><p><em>In November ‘24, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group, which exfiltrated sensitive data. After the club declined to meet the ransom demand, the ransomware gang published the full dataset on the dark web. The leaked material reportedly included player and sponsor information, and the attackers went as far as invoking GDPR exposure to pressure the club into paying, a tactic that turns a club's own regulatory obligations into leverage. </em></p><p><em>More recently, Dutch club Ajax was named among the organisations affected by the CEVA Logistics breach, where customer data was exposed through a shared shipping vendor rather than a direct compromise, underlining that supply-chain exposure is also as material a risk as any attack on a club's own estate.</em></p><p><em>Taken together, these incidents show why these rules were needed then, though they are pitched as proactive, they must also be driven by these football-related breaches.</em></p><p><em>The £100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed. The Bologna case in particular demonstrates that ransomware leaks can be damaging, which makes resilience and data minimisation far more important than any assumption that a club can negotiate its way out of trouble.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed</strong></li><li><strong>The StopAndProtect investigation revealed the WordPress content management system was key to the ring’s success; both the core software and third-party plugins were subverted</strong></li><li><strong>Around 2,000 WordPress sites were hijacked by the cybercrime ring</strong></li></ul><p>Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.</p><p>WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores.</p><p>The researchers <a href="https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/" target="_blank">found</a> the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.</p><h2 id="how-stopandprotect-did-it">How StopAndProtect did it</h2><p>WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.</p><p>While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesn’t only distribute ransomware.</p><p>Check Point Research’s Eli Smadja <a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/" target="_blank">said</a>: “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.”</p><h2 id="can-any-wordpress-domain-be-hijacked">Can any WordPress domain be hijacked?</h2><p>Given the number of WordPress sites impacted by the crime ring uncovered by the investigation, and the platform’s prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe?</p><p>“Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.</p><p>Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. </p><p>If concerns surround WordPress, the quickest solution is to ensure the website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.</p><p>Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-2-000-hacked-wordpress-sites-were-secretly-running-a-global-crime-ring</link>
                                                                            <description>
                            <![CDATA[ Compromised WordPress sites have been used by a global operation, using trusted websites to deliver malware, instruct infected devices, and even store stolen documents. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b4Zcbp8KYGsK87BPbpArpL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 22 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed</strong></li><li><strong>The StopAndProtect investigation revealed the WordPress content management system was key to the ring’s success; both the core software and third-party plugins were subverted</strong></li><li><strong>Around 2,000 WordPress sites were hijacked by the cybercrime ring</strong></li></ul><p>Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.</p><p>WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores.</p><p>The researchers <a href="https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/" target="_blank">found</a> the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.</p><h2 id="how-stopandprotect-did-it">How StopAndProtect did it</h2><p>WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.</p><p>While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesn’t only distribute ransomware.</p><p>Check Point Research’s Eli Smadja <a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/" target="_blank">said</a>: “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.”</p><h2 id="can-any-wordpress-domain-be-hijacked">Can any WordPress domain be hijacked?</h2><p>Given the number of WordPress sites impacted by the crime ring uncovered by the investigation, and the platform’s prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe?</p><p>“Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.</p><p>Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. </p><p>If concerns surround WordPress, the quickest solution is to ensure the website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.</p><p>Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn expired credit cards can be brought back from the dead to make contactless payments ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers show how an expired contactless card can still complete a real purchase because the expiry date the terminal reads is not covered by its signature</strong></li><li><strong>The attack needs physical possession of the discarded card and two ordinary smartphones, and results vary per bank, with Visa cards being susceptible in testing</strong></li><li><strong>Existing EMV protections can detect the relay, but they are optional and were not enabled on any card or terminal tested, and neither Visa nor the notified banks have confirmed a fix is in the works</strong></li></ul><p>For a layman, the date printed on a credit card looks like a hard stop, but that might not always be the case.</p><p>Researchers at the University of Massachusetts Amherst <a href="https://www.usenix.org/conference/usenixsecurity26/presentation/anwar" target="_blank" rel="nofollow">found</a> that a 'zombie card' past its expiration date can be persuaded to complete a contactless purchase at a real checkout terminal, creating a real security threat.</p><p>The irony is that it is not that EMV cryptography is not bypassed in any way, but rather that card expiry is enforced in a different way for contactless payments, as a policy check between two parties rather than as a fixed property of the card itself, and interestingly, the parties do not always know who is the one checking.</p><h2 id="dead-plastic-can-still-be-used-to-pay-under-certain-conditions">Dead plastic can still be used to pay under certain conditions</h2><p>Building on the last part, a contactless transaction involves a card, a point-of-sale terminal, the merchant's bank, a card network, and the issuer. Each holds a fragment of the decision that eventually results in a successful or declined card transaction.</p><p>The EMV contactless flow is only selectively authenticated: some fields travel between the card and terminal in unencrypted text and are linked to cryptographic verification later, opening a potential attack vector for users with physical access to an expired card.</p><p>The exposure here is not that those fields can be read, since the expiry date is printed on the card anyway, but that it can be changed with relative ease. The Application Expiration Date that the terminal reads sits in the unprotected portion.</p><p>In the Visa configuration the team tested, that field is not covered by the card's digital signature and is subsequently not cryptographically bound to the expiry value the issuer sees in the online authorization request.</p><p>While this should not be the case, it opens an attack vector for a device between the card and the terminal that processes the charge by simply modifying the expiry value to one that is still valid. The issue is compounded by a second issue: cards carry an expiry date inside the digital certificate used to establish the card-to-terminal conversation, and researchers have found that the certificate outlasts the printed date on the plastic. In essence, a check that might have caught the problem is looking at a clock set further ahead.</p><p>The scope of the attack, however, is narrow: it affects Visa contactless cards only, with Mastercard, Discover, and American Express rejecting the altered expiry outright. It also requires physical access to the card and two smartphones to pull it off, making it a slightly more complex endeavor, to say the least.</p><p>The irony is that EMV does have a protection that would essentially undo such an attempt altogether: Relay Resistance Protocol, which measures timing to detect an inserted relay and can stop the transaction altogether, but it remains optional and was not enabled on any of the terminals or cards the researchers tested.</p><p>The team notified Visa and the relevant banks in May 2025 and again in December 2025, supplying a reproduction guide, transaction traces, and a video. Visa's report passed initial triage, and the company's red team was reproducing it. </p><p>However, as of publication, neither Visa nor the notified banks had confirmed a mitigation attempt, and Visa also did not respond to a <a href="https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229" target="_blank">press request from <em>The Register</em></a> for comment.</p><p>The underlying failure, however, is based on how payment decisions have now spread across multiple players, including chip, terminal, network, and bank architectures, all of which assume that expiry is someone else's problem, an approach that could come back to haunt them and their customers. For now, the researcher's advice remains important until a fix is rolled out: stop treating dead plastic as harmless, destroy the underlying chip, and cut through the card numbers to prevent abuse.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-expired-credit-cards-can-be-brought-back-from-the-dead-to-make-contactless-payments</link>
                                                                            <description>
                            <![CDATA[ That expired card in your drawer might not be nearly as dead as you think: researchers made one pay $100 for a grocery run. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AGitkeYqa8AFsN6u8TZBRg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fL8Ba8CiJjt2qsAVpr6UmK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 21:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fL8Ba8CiJjt2qsAVpr6UmK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A credit card passed between two hands]]></media:description>                                                            <media:text><![CDATA[A credit card passed between two hands]]></media:text>
                                <media:title type="plain"><![CDATA[A credit card passed between two hands]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fL8Ba8CiJjt2qsAVpr6UmK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show how an expired contactless card can still complete a real purchase because the expiry date the terminal reads is not covered by its signature</strong></li><li><strong>The attack needs physical possession of the discarded card and two ordinary smartphones, and results vary per bank, with Visa cards being susceptible in testing</strong></li><li><strong>Existing EMV protections can detect the relay, but they are optional and were not enabled on any card or terminal tested, and neither Visa nor the notified banks have confirmed a fix is in the works</strong></li></ul><p>For a layman, the date printed on a credit card looks like a hard stop, but that might not always be the case.</p><p>Researchers at the University of Massachusetts Amherst <a href="https://www.usenix.org/conference/usenixsecurity26/presentation/anwar" target="_blank" rel="nofollow">found</a> that a 'zombie card' past its expiration date can be persuaded to complete a contactless purchase at a real checkout terminal, creating a real security threat.</p><p>The irony is that it is not that EMV cryptography is not bypassed in any way, but rather that card expiry is enforced in a different way for contactless payments, as a policy check between two parties rather than as a fixed property of the card itself, and interestingly, the parties do not always know who is the one checking.</p><h2 id="dead-plastic-can-still-be-used-to-pay-under-certain-conditions">Dead plastic can still be used to pay under certain conditions</h2><p>Building on the last part, a contactless transaction involves a card, a point-of-sale terminal, the merchant's bank, a card network, and the issuer. Each holds a fragment of the decision that eventually results in a successful or declined card transaction.</p><p>The EMV contactless flow is only selectively authenticated: some fields travel between the card and terminal in unencrypted text and are linked to cryptographic verification later, opening a potential attack vector for users with physical access to an expired card.</p><p>The exposure here is not that those fields can be read, since the expiry date is printed on the card anyway, but that it can be changed with relative ease. The Application Expiration Date that the terminal reads sits in the unprotected portion.</p><p>In the Visa configuration the team tested, that field is not covered by the card's digital signature and is subsequently not cryptographically bound to the expiry value the issuer sees in the online authorization request.</p><p>While this should not be the case, it opens an attack vector for a device between the card and the terminal that processes the charge by simply modifying the expiry value to one that is still valid. The issue is compounded by a second issue: cards carry an expiry date inside the digital certificate used to establish the card-to-terminal conversation, and researchers have found that the certificate outlasts the printed date on the plastic. In essence, a check that might have caught the problem is looking at a clock set further ahead.</p><p>The scope of the attack, however, is narrow: it affects Visa contactless cards only, with Mastercard, Discover, and American Express rejecting the altered expiry outright. It also requires physical access to the card and two smartphones to pull it off, making it a slightly more complex endeavor, to say the least.</p><p>The irony is that EMV does have a protection that would essentially undo such an attempt altogether: Relay Resistance Protocol, which measures timing to detect an inserted relay and can stop the transaction altogether, but it remains optional and was not enabled on any of the terminals or cards the researchers tested.</p><p>The team notified Visa and the relevant banks in May 2025 and again in December 2025, supplying a reproduction guide, transaction traces, and a video. Visa's report passed initial triage, and the company's red team was reproducing it. </p><p>However, as of publication, neither Visa nor the notified banks had confirmed a mitigation attempt, and Visa also did not respond to a <a href="https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229" target="_blank">press request from <em>The Register</em></a> for comment.</p><p>The underlying failure, however, is based on how payment decisions have now spread across multiple players, including chip, terminal, network, and bank architectures, all of which assume that expiry is someone else's problem, an approach that could come back to haunt them and their customers. For now, the researcher's advice remains important until a fix is rolled out: stop treating dead plastic as harmless, destroy the underlying chip, and cut through the card numbers to prevent abuse.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale —  “active threat” currently hitting energy, water and agricultural industries ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-evolved-capabilities-in-ai-generated-malware-to-hit-us-critical-infrastructure-at-an-unprecedented-scale-active-threat-currently-hitting-energy-water-and-agricultural-industries</link>
                                                                            <description>
                            <![CDATA[ The attackers are exploiting internet-facing Siemens S7 Series programmable logic controllers to scout for potential targets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QDfEDMhpgNJ3K4drrGKAGb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/supimol kumying]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:description>                                                            <media:text><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:text>
                                <media:title type="plain"><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/is-the-new-water-cyber-shield-act-too-little-too-late-and-can-a-cyber-group-do-it-better-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Numerous recent attacks are prompting Congress to do something ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tjiX2NnAd6dGXFsmpcTECc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 16 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:description>                                                            <media:text><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why was there an 'evil’ Delta airlines Wi-Fi network? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-was-there-an-evil-delta-airlines-wi-fi-network-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ A passenger set up an evil Wi-Fi network on a post-DEF CON Delta flight - we find out what the experts think. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZAjHb9bTEpdhjJqTyEPWfb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 15 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Servers & Network Devices]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Computing Components]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World-first autonomous ‘end-to-end’ AI attack against Taiwan tied to Chinese hackers — and the scariest part is that it was fully open source ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/world-first-autonomous-end-to-end-ai-attack-against-taiwan-tied-to-chinese-hackers-and-the-scariest-part-is-that-it-was-fully-open-source</link>
                                                                            <description>
                            <![CDATA[ China implicated in Taiwan attack through written documentation recovered from the attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HxPDT8x5CyBeVeFNd79h3E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:description>                                                            <media:text><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump signs memo calling for cyber privateers to conduct cyberattacks abroad against criminal groups targeting Americans — but they have to escrow $1 million to join ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/trump-signs-memo-calling-for-cyber-privateers-to-conduct-cyberattacks-abroad-against-criminal-groups-targeting-americans-but-they-have-to-escrow-usd1-million-to-join</link>
                                                                            <description>
                            <![CDATA[ Private companies will be legally allowed to conduct cyberattacks against foreign groups on behalf of the US government. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">utyNFb8pS4FFJvAbLae83g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Aug 2026 12:52:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers are using fake Odyssey pirate downloads to spread malware that's more dangerous than the Cyclops and Circe combined ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-are-using-fake-odyssey-pirate-downloads-to-spread-malware-thats-more-dangerous-than-the-cyclops-and-circe-combined</link>
                                                                            <description>
                            <![CDATA[ Fake downloads of The Odyssey are delivering Lumma Stealer, and the stolen session cookies walk straight past your two-factor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xoShk7grh9qqbbQ4g5pjNT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg">
                                                            <media:credit><![CDATA[Universal Studios]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:description>                                                            <media:text><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:text>
                                <media:title type="plain"><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp scam costs Hong Kong man $1.27 million after criminals used AI voice notes to impersonate his father — experts say secret codewords are the best way to stay safe ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Scammers stole $1.27m from a Hong Kong man after tricking him with AI</strong></li><li><strong>The scheme impersonated his father using AI deepfake tech</strong></li><li><strong>Experts say using a secret codeword can thwart the fraudsters</strong></li></ul><p>A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence (AI)</a> on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate. </p><p>According to the Hong Kong police’s Cyberdefender platform (via the <a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3362297/hong-kong-raises-alert-ai-voices-150-whatsapp-hijackings-lead-hk26m-losses" target="_blank">South China Morning Post</a>), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000). </p><p>This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings. </p><p>Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.” </p><p>If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling <a href="https://www.techradar.com/best/best-authenticator-apps">two-factor authentication</a> on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.</p><h2 id="how-to-beat-the-fraudsters">How to beat the fraudsters</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="q6xnz9NJyKA7z3WTRVAFwK" name="WhatsApp by Brett Jordan on Unsplash" alt="The WhatsApp icon on an iPhone's display." src="https://cdn.mos.cms.futurecdn.net/q6xnz9NJyKA7z3WTRVAFwK.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Brett Jordan / Unsplash)</span></figcaption></figure><p>Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe. </p><p>As reported by the <a href="https://www.bbc.co.uk/future/article/20260804-why-your-family-needs-a-secret-codeword" target="_blank">BBC</a>, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.” </p><p>One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity. </p><p>When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.” </p><p>As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, <a href="https://www.techradar.com/pro/bitcoins-record-highs-spark-a-surge-in-crypto-scams">cryptocurrency</a> or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist. </p><p>Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/cybercrime/whatsapp-scam-costs-hong-kong-man-usd1-27-million-after-criminals-used-ai-voice-notes-to-impersonate-his-father-experts-say-secret-codewords-are-the-best-way-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Scammers used AI to steal $1.27 million from a Hong Kong man as experts say a secret codeword can keep you safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nk2apuRFNZu9gsP8Li3R5Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RvMugdp92V42urozAU4JYo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 21:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RvMugdp92V42urozAU4JYo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ronstik]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand holding a phone showing a call from an unknown number]]></media:description>                                                            <media:text><![CDATA[A hand holding a phone showing a call from an unknown number]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a phone showing a call from an unknown number]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RvMugdp92V42urozAU4JYo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers stole $1.27m from a Hong Kong man after tricking him with AI</strong></li><li><strong>The scheme impersonated his father using AI deepfake tech</strong></li><li><strong>Experts say using a secret codeword can thwart the fraudsters</strong></li></ul><p>A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence (AI)</a> on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate. </p><p>According to the Hong Kong police’s Cyberdefender platform (via the <a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3362297/hong-kong-raises-alert-ai-voices-150-whatsapp-hijackings-lead-hk26m-losses" target="_blank">South China Morning Post</a>), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000). </p><p>This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings. </p><p>Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.” </p><p>If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling <a href="https://www.techradar.com/best/best-authenticator-apps">two-factor authentication</a> on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.</p><h2 id="how-to-beat-the-fraudsters">How to beat the fraudsters</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="q6xnz9NJyKA7z3WTRVAFwK" name="WhatsApp by Brett Jordan on Unsplash" alt="The WhatsApp icon on an iPhone's display." src="https://cdn.mos.cms.futurecdn.net/q6xnz9NJyKA7z3WTRVAFwK.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Brett Jordan / Unsplash)</span></figcaption></figure><p>Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe. </p><p>As reported by the <a href="https://www.bbc.co.uk/future/article/20260804-why-your-family-needs-a-secret-codeword" target="_blank">BBC</a>, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.” </p><p>One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity. </p><p>When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.” </p><p>As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, <a href="https://www.techradar.com/pro/bitcoins-record-highs-spark-a-surge-in-crypto-scams">cryptocurrency</a> or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist. </p><p>Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI agent accused of stealing $1 million in crypto — and he even consulted ChatGPT on how to leave the country ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A former FBI counterintelligence supervisor is accused of memorizing seed phrases from bureau systems</strong></li><li><strong>The agent moved roughly $1 million out of wallets tied to a foreign adversary without having to resort to any sort of hacking</strong></li><li><strong>Investigators recovered ChatGPT conversations in which he asked how to invest the money and how to gain EU residency, and the chatbot's replies recited his age, wife, child, and property plans back to him</strong></li></ul><p>Patrick Steven Yaroch, a supervisory special agent in the FBI's Counterintelligence and Espionage Division, has been arrested and charged with interstate transportation and receipt of stolen goods.</p><p>An affidavit filed in the Eastern District of Virginia, claims Yaroch took roughly a million dollars in cryptocurrency from wallets he encountered while investigating a foreign adversary and then used ChatGPT to determine what to do with it.</p><p>The theft, as described, required no technical sophistication whatsoever: Yaroch held a Top Secret clearance with SCI access and had spent 2017 to 2025 on a national security squad at the FBI's Boston division working against a single adversarial nation, which <a href="https://www.nbcnews.com/politics/justice-department/feds-charge-fbi-agent-say-stole-nearly-one-million-crypto-russia-rcna590674" target="_blank">NBC News reports was Russia</a>. </p><h2 id="an-atypical-heist-with-the-alleged-mastermind-acting-out-of-frustration">An atypical heist with the alleged mastermind acting out of "frustration"</h2><p>Patrick Steven Yaroch encountered the cryptocurrency wallets tied to his work in November 2024. He had researched how wallets work, created one of his own, searched the FBI's holdings for the relevant account information, and memorized the recovery seed phrases.</p><p>He then made roughly 10-12 transfers to his own wallet. No encryption was broken, and no protocol was exploited because none was in place for a man with his security clearance; he simply read a phrase off an internal system and remembered it.</p><p>The incident is particularly interesting because he self-reported, effectively turning himself in to his colleagues: on July 28 2026, he contacted a Justice Department employee he had worked with in Boston over Signal, asking to meet. They met at FBI headquarters the next day, where Yaroch reportedly began breaking down almost immediately, and the conversation moved to the other man's office.</p><p>He said the situation was "eating him up inside" and that he wanted to give all the money back. He filed an online self-report to the FBI's Security Division and told headquarters personnel he had screwed up. When agents arrived at his Ashburn home that evening, he told them, unprompted and in blunter terms, that he had messed up.</p><p>His defense, as per the affidavit, however, is slightly different from what one would expect: His stated motive was not greed. He told his colleagues he had grown frustrated that the FBI could not or would not act against those accounts, described himself as "spinning out of control" at the time, and said he decided to take matters into his own hands.</p><p>Despite this, he seemingly had a change of heart after cooperating earlier, asking for a paper containing his wallet seed phrases, which he had volunteered to agents, while declining to continue the interview without a lawyer while asking for time over the next two days.</p><p>This culminated in agents obtaining warrants, executing them on July 31 with SWAT securing the house, and recovering an iPhone, a Trezor hardware wallet, the handwritten seed phrases, a Portuguese power of attorney dated June 15, and three passports, one of them diplomatic.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pwcbaLVSvqWvfTPCXUPoQD" name="shutterstock_1173443506.jpg" alt="Man annoyed at laptop" src="https://cdn.mos.cms.futurecdn.net/pwcbaLVSvqWvfTPCXUPoQD.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Marjan Apostolovic / Shutterstock)</span></figcaption></figure><p>Ironically, the most potentially damning evidence of his intentions comes from his conversations with AI, still on his phone and directly linked to him. </p><p>His conversations with ChatGPT convey a very different thought process: On May 28, he asked how to invest or spend a million dollars to maximize profit and return. On June 4, he asked what someone with about a million dollars should do to leave the United States and become a resident or citizen of an EU country. On June 17 he asked whether an American connecting through Turkey needs a visa. On June 26 he asked for help drafting an email to an executive about a job opening and life in Greece.</p><p>There is more evidence that he might already have acted based on the answers he received: prosecutors have found a power of attorney authorizing two Portuguese lawyers to register him with the country's tax authority and obtain a Portuguese tax identification number, and unreported foreign travel to Germany in May, Portugal later that month, and Grenada in early July, all in breach of bureau reporting rules.</p><p>His current investments seem to be equally erratically reasoned: On July 23, five days before he first confessed, Yaroch moved roughly $1.02 million into Suilend, a lending protocol on the Sui blockchain, reaching it through the Slush wallet app, which he then deleted. He parked the funds there to earn interest. When asked why he chose that service, he said he liked its logo, a water droplet.</p><p>When agents looked, the position was worth $933,756, roughly 8% below its level a week earlier. His Kraken account held another $188,570, including about $5,000 in a token called Squid and $1.67 in Bitcoin. Agents ultimately swept $925,426 into government wallets, leaving about $165,582 behind because it was dollars and could not be moved to a crypto wallet.</p><p>Yaroch is charged under sections 2314 and 2315 of the federal criminal code, the general provisions on transporting and receiving stolen goods. He is not charged with espionage, with computer fraud, or with theft of government property.</p><p>The wallets were not the government's, and that might change how they are treated legally, even as it raises important questions about the security protocols at federal agencies regarding cryptocurrencies, since they both monitor and have <a href="https://www.techradar.com/pro/security/huge-cryptomixer-takedown-sees-feds-seize-over-usd30milion" target="_blank">seized increasingly large amounts</a> of them over the past few years.</p><p>In Yaroch's case, if the allegations hold, government protocols failed to identify the theft for nearly eighteen months before the person responsible reported himself, making the case for a potential review by federal agencies about how they handle such matters.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/fbi-agent-accused-of-stealing-usd1-million-in-crypto-and-he-even-consulted-chatgpt-on-how-to-leave-the-country</link>
                                                                            <description>
                            <![CDATA[ An FBI agent allegedly stole $1m in crypto by memorizing a seed phrase, then asked ChatGPT how to move to Europe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QB9Wnq49JxXT4j3oVymeza</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y5BaBkp9uJ2RQnJbCbDEsA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 23:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y5BaBkp9uJ2RQnJbCbDEsA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Yevhen Vitte]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[.]]></media:description>                                                            <media:text><![CDATA[Crypto mining]]></media:text>
                                <media:title type="plain"><![CDATA[Crypto mining]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y5BaBkp9uJ2RQnJbCbDEsA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A former FBI counterintelligence supervisor is accused of memorizing seed phrases from bureau systems</strong></li><li><strong>The agent moved roughly $1 million out of wallets tied to a foreign adversary without having to resort to any sort of hacking</strong></li><li><strong>Investigators recovered ChatGPT conversations in which he asked how to invest the money and how to gain EU residency, and the chatbot's replies recited his age, wife, child, and property plans back to him</strong></li></ul><p>Patrick Steven Yaroch, a supervisory special agent in the FBI's Counterintelligence and Espionage Division, has been arrested and charged with interstate transportation and receipt of stolen goods.</p><p>An affidavit filed in the Eastern District of Virginia, claims Yaroch took roughly a million dollars in cryptocurrency from wallets he encountered while investigating a foreign adversary and then used ChatGPT to determine what to do with it.</p><p>The theft, as described, required no technical sophistication whatsoever: Yaroch held a Top Secret clearance with SCI access and had spent 2017 to 2025 on a national security squad at the FBI's Boston division working against a single adversarial nation, which <a href="https://www.nbcnews.com/politics/justice-department/feds-charge-fbi-agent-say-stole-nearly-one-million-crypto-russia-rcna590674" target="_blank">NBC News reports was Russia</a>. </p><h2 id="an-atypical-heist-with-the-alleged-mastermind-acting-out-of-frustration">An atypical heist with the alleged mastermind acting out of "frustration"</h2><p>Patrick Steven Yaroch encountered the cryptocurrency wallets tied to his work in November 2024. He had researched how wallets work, created one of his own, searched the FBI's holdings for the relevant account information, and memorized the recovery seed phrases.</p><p>He then made roughly 10-12 transfers to his own wallet. No encryption was broken, and no protocol was exploited because none was in place for a man with his security clearance; he simply read a phrase off an internal system and remembered it.</p><p>The incident is particularly interesting because he self-reported, effectively turning himself in to his colleagues: on July 28 2026, he contacted a Justice Department employee he had worked with in Boston over Signal, asking to meet. They met at FBI headquarters the next day, where Yaroch reportedly began breaking down almost immediately, and the conversation moved to the other man's office.</p><p>He said the situation was "eating him up inside" and that he wanted to give all the money back. He filed an online self-report to the FBI's Security Division and told headquarters personnel he had screwed up. When agents arrived at his Ashburn home that evening, he told them, unprompted and in blunter terms, that he had messed up.</p><p>His defense, as per the affidavit, however, is slightly different from what one would expect: His stated motive was not greed. He told his colleagues he had grown frustrated that the FBI could not or would not act against those accounts, described himself as "spinning out of control" at the time, and said he decided to take matters into his own hands.</p><p>Despite this, he seemingly had a change of heart after cooperating earlier, asking for a paper containing his wallet seed phrases, which he had volunteered to agents, while declining to continue the interview without a lawyer while asking for time over the next two days.</p><p>This culminated in agents obtaining warrants, executing them on July 31 with SWAT securing the house, and recovering an iPhone, a Trezor hardware wallet, the handwritten seed phrases, a Portuguese power of attorney dated June 15, and three passports, one of them diplomatic.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pwcbaLVSvqWvfTPCXUPoQD" name="shutterstock_1173443506.jpg" alt="Man annoyed at laptop" src="https://cdn.mos.cms.futurecdn.net/pwcbaLVSvqWvfTPCXUPoQD.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Marjan Apostolovic / Shutterstock)</span></figcaption></figure><p>Ironically, the most potentially damning evidence of his intentions comes from his conversations with AI, still on his phone and directly linked to him. </p><p>His conversations with ChatGPT convey a very different thought process: On May 28, he asked how to invest or spend a million dollars to maximize profit and return. On June 4, he asked what someone with about a million dollars should do to leave the United States and become a resident or citizen of an EU country. On June 17 he asked whether an American connecting through Turkey needs a visa. On June 26 he asked for help drafting an email to an executive about a job opening and life in Greece.</p><p>There is more evidence that he might already have acted based on the answers he received: prosecutors have found a power of attorney authorizing two Portuguese lawyers to register him with the country's tax authority and obtain a Portuguese tax identification number, and unreported foreign travel to Germany in May, Portugal later that month, and Grenada in early July, all in breach of bureau reporting rules.</p><p>His current investments seem to be equally erratically reasoned: On July 23, five days before he first confessed, Yaroch moved roughly $1.02 million into Suilend, a lending protocol on the Sui blockchain, reaching it through the Slush wallet app, which he then deleted. He parked the funds there to earn interest. When asked why he chose that service, he said he liked its logo, a water droplet.</p><p>When agents looked, the position was worth $933,756, roughly 8% below its level a week earlier. His Kraken account held another $188,570, including about $5,000 in a token called Squid and $1.67 in Bitcoin. Agents ultimately swept $925,426 into government wallets, leaving about $165,582 behind because it was dollars and could not be moved to a crypto wallet.</p><p>Yaroch is charged under sections 2314 and 2315 of the federal criminal code, the general provisions on transporting and receiving stolen goods. He is not charged with espionage, with computer fraud, or with theft of government property.</p><p>The wallets were not the government's, and that might change how they are treated legally, even as it raises important questions about the security protocols at federal agencies regarding cryptocurrencies, since they both monitor and have <a href="https://www.techradar.com/pro/security/huge-cryptomixer-takedown-sees-feds-seize-over-usd30milion" target="_blank">seized increasingly large amounts</a> of them over the past few years.</p><p>In Yaroch's case, if the allegations hold, government protocols failed to identify the theft for nearly eighteen months before the person responsible reported himself, making the case for a potential review by federal agencies about how they handle such matters.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>New study puts average cybercrime victim losses at $9,468, making a global annual toll at just over $1.24 trillion across 130.9 million victims</strong></li><li><strong>Cybercrime is still massively underreported by both victims and authorities, so official numbers might be 'softer' than the underlying problem</strong></li><li><strong>Some of the countries published limited, if any, financial data regarding cybercrime, making losses an estimate at best</strong></li></ul><p>New figures have claimed cybercrime victims lose $9,468 in the average incident, showing the scale of an increasingly global problem.</p><p>The report from Comparitech claims 130.9 million people are hit each year, and that the annual global toll comes to just over $1.24 trillion.</p><p>A December 2023 study from the company put those figures at $8,069 per victim, 88.5 million people and $714 billion in total losses respectively, highlighting a growing trend that sees a mix of illegal activity moving the needle further.</p><h2 id="a-growing-problem-with-regional-caveats">A growing problem with regional caveats</h2><p>The United States remains a favorite for cybercriminals, topping the charts with 6.7 million victims losing $138.9 billion, a per-victim loss amount of ~$20,731, more than twice that of the global average.</p><p>This is in stark contrast with the next four countries on the list (Spain, France, Sweden and Turkey), all of which offered an average of approximately $10,000 per victim.</p><p>Russia, coming in 6th, reports a much larger number of victims than the four countries ahead of it, but offers a much lower per-victim loss estimate of $3,659. Interestingly, the total number of cybercrimes committed in 2025 dropped to 663,000 from 775,000 in 2024, despite an ongoing conflict with Ukraine, which <a href="https://www.techradar.com/pro/ukraines-largest-mobile-network-goes-down-after-massive-cyberattack" target="_blank">often sees cyberattacks at both the industrial</a> and localized levels by both parties.</p><p>However, a weakening economic situation, as well as Russia localizing many of its communication applications and restricting banking, might also mean that Russia's figures also remain inadvertently capped by policy decisions the country has taken.</p><p>With 18.8 million victims, India has the highest number of scam victims worldwide, even though its pro-rata number is considerably lower than the mean at ~$835 per victim, which may be attributable to the country's lower GDP per capita.</p><p>Interestingly, China, with 1.2 million victims, a fraction of its neighbor, managed to lose approximately $11.5 billion, a pro-rata number of approximately $9583, in line with global estimates by Comparitech and possibly fueled by the country's heavy-handed approach to cybercriminals, which saw it apply increasing amounts of pressure on neighboring Myanmar that culminated in it <a href="https://www.bbc.com/news/articles/cx2gdrvy9gjo" target="_blank">convicting and executing scammers</a> arrested across the border.</p><p>Comparitech's $1.24 trillion figure is conservative, and the study acknowledges this, noting that it covers only victim losses. It notes that experts anticipated the global cost reaching $10.5 trillion in 2025 and calls its own $1.24 trillion a drop in the ocean by comparison.</p><p>That $10.5 trillion comes from Cybersecurity Ventures' 2016 report, which estimated $3 trillion for 2015 and projected it forward at an assumed 15 percent compound annual growth rate, describing the result as the greatest transfer of economic wealth in history.</p><p>At a time when AI automation offers better security, often allowing users to screen calls or leverage security applications that adapt on a case-by-case basis, the inverse is also true with hackers and cybercriminals <a href="https://www.techradar.com/pro/why-traditional-security-checks-are-failing-in-the-age-of-ai-driven-fraud" target="_blank">considerably upping their game</a> when it comes to bypassing security altogether; Comparitech's figures provide a sobering reality: if the industry estimates it has hold and are compared to the GDP of entire countries, the firm says it would rank 20th in the world in those terms alone.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit</link>
                                                                            <description>
                            <![CDATA[ An increasingly expensive situation at a global scale ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3Sr9bYgxviKgxk7JhGdFPP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 22:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>New study puts average cybercrime victim losses at $9,468, making a global annual toll at just over $1.24 trillion across 130.9 million victims</strong></li><li><strong>Cybercrime is still massively underreported by both victims and authorities, so official numbers might be 'softer' than the underlying problem</strong></li><li><strong>Some of the countries published limited, if any, financial data regarding cybercrime, making losses an estimate at best</strong></li></ul><p>New figures have claimed cybercrime victims lose $9,468 in the average incident, showing the scale of an increasingly global problem.</p><p>The report from Comparitech claims 130.9 million people are hit each year, and that the annual global toll comes to just over $1.24 trillion.</p><p>A December 2023 study from the company put those figures at $8,069 per victim, 88.5 million people and $714 billion in total losses respectively, highlighting a growing trend that sees a mix of illegal activity moving the needle further.</p><h2 id="a-growing-problem-with-regional-caveats">A growing problem with regional caveats</h2><p>The United States remains a favorite for cybercriminals, topping the charts with 6.7 million victims losing $138.9 billion, a per-victim loss amount of ~$20,731, more than twice that of the global average.</p><p>This is in stark contrast with the next four countries on the list (Spain, France, Sweden and Turkey), all of which offered an average of approximately $10,000 per victim.</p><p>Russia, coming in 6th, reports a much larger number of victims than the four countries ahead of it, but offers a much lower per-victim loss estimate of $3,659. Interestingly, the total number of cybercrimes committed in 2025 dropped to 663,000 from 775,000 in 2024, despite an ongoing conflict with Ukraine, which <a href="https://www.techradar.com/pro/ukraines-largest-mobile-network-goes-down-after-massive-cyberattack" target="_blank">often sees cyberattacks at both the industrial</a> and localized levels by both parties.</p><p>However, a weakening economic situation, as well as Russia localizing many of its communication applications and restricting banking, might also mean that Russia's figures also remain inadvertently capped by policy decisions the country has taken.</p><p>With 18.8 million victims, India has the highest number of scam victims worldwide, even though its pro-rata number is considerably lower than the mean at ~$835 per victim, which may be attributable to the country's lower GDP per capita.</p><p>Interestingly, China, with 1.2 million victims, a fraction of its neighbor, managed to lose approximately $11.5 billion, a pro-rata number of approximately $9583, in line with global estimates by Comparitech and possibly fueled by the country's heavy-handed approach to cybercriminals, which saw it apply increasing amounts of pressure on neighboring Myanmar that culminated in it <a href="https://www.bbc.com/news/articles/cx2gdrvy9gjo" target="_blank">convicting and executing scammers</a> arrested across the border.</p><p>Comparitech's $1.24 trillion figure is conservative, and the study acknowledges this, noting that it covers only victim losses. It notes that experts anticipated the global cost reaching $10.5 trillion in 2025 and calls its own $1.24 trillion a drop in the ocean by comparison.</p><p>That $10.5 trillion comes from Cybersecurity Ventures' 2016 report, which estimated $3 trillion for 2015 and projected it forward at an assumed 15 percent compound annual growth rate, describing the result as the greatest transfer of economic wealth in history.</p><p>At a time when AI automation offers better security, often allowing users to screen calls or leverage security applications that adapt on a case-by-case basis, the inverse is also true with hackers and cybercriminals <a href="https://www.techradar.com/pro/why-traditional-security-checks-are-failing-in-the-age-of-ai-driven-fraud" target="_blank">considerably upping their game</a> when it comes to bypassing security altogether; Comparitech's figures provide a sobering reality: if the industry estimates it has hold and are compared to the GDP of entire countries, the firm says it would rank 20th in the world in those terms alone.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'We’ve been behind the ball for so long': Experts say DNA samples from crime-scene forensics can be modified and even switched using an AI tool ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers discover critical vulnerability in forensic software that allows the undetectable modification of DNA samples on crime-scene evidence</strong></li><li><strong>The vulnerability allows much of the crime-scene evidence from the past 30 years to be modified</strong></li><li><strong>A patch is in the works, and the company responsible for the software says that digital signatures have been implemented to monitor for modification attempts</strong></li></ul><p>A group of forensic and computer scientists have raised concerns about the security of software used by top US crime labs to analyze DNA evidence.</p><p>By using an AI model, the researchers were able to undetectably modify computerized scans of physical DNA evidence, exclusive <a href="https://www.wsj.com/tech/cybersecurity/security-flaw-placed-30-years-of-dna-evidence-at-risk-of-hacking-1932775a?st=zGgyGg&reflink=desktopwebshare_permalink" target="_blank" rel="nofollow"><em>Wall Street Journal</em></a> reported. As the vulnerability relates to digital files made by crime labs since 1995, the vulnerability places 30 years of crime files at risk of being tampered with.</p><p>“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag,” said Laura Gaydosh Combs, a University of New Haven professor and forensic scientist who contributed to the research.</p><h2 id="no-known-instances-of-undetectable-exploitation">No known instances of ‘undetectable’ exploitation</h2><p>The researchers disclosed the vulnerability in May. Thermo Fisher Scientific, the company that builds the crime-lab equipment used across most US facilities, privately acknowledging the vulnerability in July 2026. The company said that a fix is currently in progress.</p><p>In a separate note to customers, Thermo Fisher Scientific said there were no known instances of the vulnerability being exploited.</p><p>But the researchers themselves have said that they could not find a way to detect if tampering had taken place. The vulnerability was tested by Nathan Adams, a systems engineer at Forensic Bioinformatics. In just 45 minutes, Adams managed to successfully exploit the vulnerability using Anthropic’s Claude, and modify a file.</p><p>Despite some of the files being sealed using a more advanced encryption algorithm, Adams was able to find and use a decryption key available on the internet to crack into these files.</p><p>The researchers highlighted that by using AI tools to gain the necessary skills and tools, a hacker could abuse the vulnerability to add or remove DNA profiles from crime-scene evidence. Therefore allowing a suspect’s DNA to be removed, or an innocent person’s DNA added.</p><p>“Lessons learned from other industries haven’t been imported into forensic science in a serious way,” said Sarah Chu, the director of policy and reform at the Perlmutter Center for Legal Justice who worked on the research. “We’ve been behind the ball for so long. That kind of all rolls downhill into this incident.”</p><p>The lack of any centralized regulator on forensics has left over 200 labs with a patchwork of security measures, Chu added.</p><p>In a statement to the <em>WSJ</em>, Thermo Fisher Scientific said, “We have been working closely with the U.S. Cybersecurity and Infrastructure Agency since the software issue was raised. We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/weve-been-behind-the-ball-for-so-long-experts-say-dna-samples-from-crime-scene-forensics-can-be-modified-and-even-switched-using-an-ai-tool</link>
                                                                            <description>
                            <![CDATA[ Researchers used AI-assisted code to undetectably tamper with data from computerized scans of physical DNA evidence produced by widely used crime-lab machines. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QbpyNnGanZuZwAT2oRz9w8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HWb2cSJ4Mb5mxx8ebgiAzH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Aug 2026 13:08:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HWb2cSJ4Mb5mxx8ebgiAzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A forensic police officer examines a smartphone as evidence in a murder case at a forensic laboratory]]></media:description>                                                            <media:text><![CDATA[A forensic police officer examines a smartphone as evidence in a murder case at a forensic laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[A forensic police officer examines a smartphone as evidence in a murder case at a forensic laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HWb2cSJ4Mb5mxx8ebgiAzH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers discover critical vulnerability in forensic software that allows the undetectable modification of DNA samples on crime-scene evidence</strong></li><li><strong>The vulnerability allows much of the crime-scene evidence from the past 30 years to be modified</strong></li><li><strong>A patch is in the works, and the company responsible for the software says that digital signatures have been implemented to monitor for modification attempts</strong></li></ul><p>A group of forensic and computer scientists have raised concerns about the security of software used by top US crime labs to analyze DNA evidence.</p><p>By using an AI model, the researchers were able to undetectably modify computerized scans of physical DNA evidence, exclusive <a href="https://www.wsj.com/tech/cybersecurity/security-flaw-placed-30-years-of-dna-evidence-at-risk-of-hacking-1932775a?st=zGgyGg&reflink=desktopwebshare_permalink" target="_blank" rel="nofollow"><em>Wall Street Journal</em></a> reported. As the vulnerability relates to digital files made by crime labs since 1995, the vulnerability places 30 years of crime files at risk of being tampered with.</p><p>“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag,” said Laura Gaydosh Combs, a University of New Haven professor and forensic scientist who contributed to the research.</p><h2 id="no-known-instances-of-undetectable-exploitation">No known instances of ‘undetectable’ exploitation</h2><p>The researchers disclosed the vulnerability in May. Thermo Fisher Scientific, the company that builds the crime-lab equipment used across most US facilities, privately acknowledging the vulnerability in July 2026. The company said that a fix is currently in progress.</p><p>In a separate note to customers, Thermo Fisher Scientific said there were no known instances of the vulnerability being exploited.</p><p>But the researchers themselves have said that they could not find a way to detect if tampering had taken place. The vulnerability was tested by Nathan Adams, a systems engineer at Forensic Bioinformatics. In just 45 minutes, Adams managed to successfully exploit the vulnerability using Anthropic’s Claude, and modify a file.</p><p>Despite some of the files being sealed using a more advanced encryption algorithm, Adams was able to find and use a decryption key available on the internet to crack into these files.</p><p>The researchers highlighted that by using AI tools to gain the necessary skills and tools, a hacker could abuse the vulnerability to add or remove DNA profiles from crime-scene evidence. Therefore allowing a suspect’s DNA to be removed, or an innocent person’s DNA added.</p><p>“Lessons learned from other industries haven’t been imported into forensic science in a serious way,” said Sarah Chu, the director of policy and reform at the Perlmutter Center for Legal Justice who worked on the research. “We’ve been behind the ball for so long. That kind of all rolls downhill into this incident.”</p><p>The lack of any centralized regulator on forensics has left over 200 labs with a patchwork of security measures, Chu added.</p><p>In a statement to the <em>WSJ</em>, Thermo Fisher Scientific said, “We have been working closely with the U.S. Cybersecurity and Infrastructure Agency since the software issue was raised. We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California</strong></li><li><strong>The vulnerability is due to dealer-installed security systems</strong></li><li><strong>Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key</strong></li></ul><p>A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.</p><p>Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.</p><p>Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.</p><h2 id="how-bluetooth-controls-these-cars">How Bluetooth controls these cars</h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/xS_4dNRGkoA" allowfullscreen></iframe></div></div><p>The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard. </p><p>Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running. </p><p>The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.</p><p>Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.</p><p>“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”</p><h2 id="the-patch-is-in">The patch is in</h2><p>Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”</p><p>KARR has <a href="https://www.theregister.com/security/2026/07/23/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth/5277315" target="_blank">told</a> media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a <a href="https://www.karrsecurity.com/karr-security-firmware-update-instructions" target="_blank">firmware update</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-2-2-million-cars-could-be-at-risk-of-hijacking-via-bluetooth</link>
                                                                            <description>
                            <![CDATA[ Researchers find dealer-installed KARR and SWDS security systems are open to a Bluetooth-based hack which can remotely unlock doors and stop a vehicle from starting. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">G7JrH4KatQ5aFECzCy6c4f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jul 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand over a concealed car door handle]]></media:description>                                                            <media:text><![CDATA[A hand over a concealed car door handle]]></media:text>
                                <media:title type="plain"><![CDATA[A hand over a concealed car door handle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California</strong></li><li><strong>The vulnerability is due to dealer-installed security systems</strong></li><li><strong>Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key</strong></li></ul><p>A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.</p><p>Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.</p><p>Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.</p><h2 id="how-bluetooth-controls-these-cars">How Bluetooth controls these cars</h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/xS_4dNRGkoA" allowfullscreen></iframe></div></div><p>The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard. </p><p>Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running. </p><p>The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.</p><p>Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.</p><p>“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”</p><h2 id="the-patch-is-in">The patch is in</h2><p>Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”</p><p>KARR has <a href="https://www.theregister.com/security/2026/07/23/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth/5277315" target="_blank">told</a> media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a <a href="https://www.karrsecurity.com/karr-security-firmware-update-instructions" target="_blank">firmware update</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake FBI social media scams are on the rise — here's what to look out for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Scammers are pretending to offer FBI support to victims</strong></li><li><strong>Victims are becoming double-victims after falling for this trap</strong></li><li><strong>FBI's IC3 warns never to pay for support – support will come from law enforcement</strong></li></ul><p>Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.</p><p>Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.</p><p>But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.</p><h2 id="victims-are-being-hit-twice-via-fake-fbi-scams">Victims are being hit twice via fake FBI scams</h2><p>Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank">explained</a>.</p><p>In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates. </p><p>"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."</p><p>Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fake-fbi-social-media-scams-are-on-the-rise-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Victims reporting crimes to the FBI are actually being caught and revictimized, leading to further financial losses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3zSRMcDm3LticiguF3F3Nh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers are pretending to offer FBI support to victims</strong></li><li><strong>Victims are becoming double-victims after falling for this trap</strong></li><li><strong>FBI's IC3 warns never to pay for support – support will come from law enforcement</strong></li></ul><p>Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.</p><p>Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.</p><p>But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.</p><h2 id="victims-are-being-hit-twice-via-fake-fbi-scams">Victims are being hit twice via fake FBI scams</h2><p>Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank">explained</a>.</p><p>In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates. </p><p>"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."</p><p>Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US sanctions on rogue VPN accidentally break Telegram's short links worldwide ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The US Treasury sanctioned First VPN Service for aiding ransomware gangs</strong></li><li><strong>Complying with the sanctions, the .ME registry wrongly suspended Telegram's entire t.me domain</strong></li><li><strong>The domain was restored roughly 19 hours later after Telegram CEO Pavel Durov flagged the issue online</strong></li></ul><p>If you clicked a Telegram link on Monday and stared at a blank screen, you weren't alone. Every shortlink starting with 't.me' suddenly vanished from the global internet, breaking group invites, profile shares, and channel links for roughly a billion users worldwide.</p><p>But the outage wasn't caused by a technical glitch or a targeted cyberattack. Instead, it was the unintended collateral damage of a US government crackdown on a cybercriminal proxy network.</p><p>On July 13, the US Treasury Department's Office of Foreign Assets Control (OFAC) <a href="https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks">sanctioned the administrators of a rogue proxy network</a> called First VPN Service (1VPNS), aiming to cut off infrastructure used by ransomware operators. </p><p>While anyone shopping for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> expects privacy, First VPN actively courted cybercriminals with promises of total anonymity, leading <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">European law enforcement to pull the plug on the service</a> earlier in May.</p><p>As part of the new sanctions, the US Treasury published a list of web addresses associated with the VPN. Buried in that list was a link to First VPN's public Telegram support channel: t.me/FirstVPNService.</p><h2 id="a-sledgehammer-to-crack-a-nut">A sledgehammer to crack a nut</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qp6PFkub49CUBhgFaHwjeQ" name="First VPN" alt="This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, "This service has been seized"" src="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)</span></figcaption></figure><p>Because top-level domains operate under strict international compliance rules, domain registrars must act quickly when sanctioned entities use their infrastructure.</p><p>Identity Digital, the company managing the technical backend for the .me domain, <a href="https://meduza.io/en/news/2026/07/14/u-s-treasury-sanctions-on-a-vpn-service-knocked-out-telegram-s-short-link-domain-worldwide" target="_blank" rel="nofollow">confirmed that the t.me domain had been blocked</a> at the request of OFAC. </p><p>However, because a domain registry cannot selectively disable a specific webpage or channel path — like a single Telegram group — the Montenegro-based registry Domain.Me applied a "serverHold" status to Telegram's entire t.me domain.</p><p>This sweeping action effectively erased the domain from the global <a href="https://www.techradar.com/vpn/what-is-dns">Domain Name System (DNS)</a>. The core Telegram app continued to function, and the older telegram.me domain remained active, but the shortlinks the messaging platform is built upon went entirely dark.</p><h2 id="the-swift-resolution">The swift resolution</h2><p>The sudden shutdown prompted immediate action from Telegram's leadership. </p><p>Unaware of the backend domain hold, Telegram CEO Pavel Durov <a href="https://x.com/durov/status/2076836338117046660" target="_blank" rel="nofollow">took to X</a> to publicly ask the registrar for an explanation: "Hey @domainME, t.me links stopped working. Can you look into it?"</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2076836338117046660"><p lang="en" dir="ltr">Hey @domainME, https://t.co/9z6UC2o37U links stopped working. Can you look into it? 🙏<a href="https://twitter.com/cantworkitout/status/2076836338117046660">July 14, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Once the sanctions issue was identified, Telegram scrubbed the offending channels from its platform. The registry operator subsequently verified the compliance and brought the domain back online.</p><p>"On 13 July, 1VPNS was included as a sanctioned entity by the US Department of the Treasury. A Telegram channel using the t.me domain was among 1VPNS identified infrastructure. Accordingly, the t.me domain was suspended," domain.Me confirmed in a <a href="https://x.com/domainme/status/2077077395777994942" target="_blank" rel="nofollow">statement<u> </u></a>following the outage.</p><p>The registrar clarified that normal service resumed roughly a day later, after Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. "We appreciate Telegram's prompt cooperation in resolving this matter," domain.Me added.</p><p>While the outage is now resolved, the incident highlights a glaring vulnerability in the modern web, where a single URL swept up in a government sanctions list can inadvertently silence an essential communication channel for millions.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/us-sanctions-on-rogue-vpn-accidentally-break-telegrams-short-links-worldwide</link>
                                                                            <description>
                            <![CDATA[ Telegram’s t.me domain was swept up in a global outage following US Treasury sanctions against First VPN services, causing millions of web links to break worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4P42CJuXVG9W8YZrgU7CEJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:43:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Milman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaque Silva/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury sanctioned First VPN Service for aiding ransomware gangs</strong></li><li><strong>Complying with the sanctions, the .ME registry wrongly suspended Telegram's entire t.me domain</strong></li><li><strong>The domain was restored roughly 19 hours later after Telegram CEO Pavel Durov flagged the issue online</strong></li></ul><p>If you clicked a Telegram link on Monday and stared at a blank screen, you weren't alone. Every shortlink starting with 't.me' suddenly vanished from the global internet, breaking group invites, profile shares, and channel links for roughly a billion users worldwide.</p><p>But the outage wasn't caused by a technical glitch or a targeted cyberattack. Instead, it was the unintended collateral damage of a US government crackdown on a cybercriminal proxy network.</p><p>On July 13, the US Treasury Department's Office of Foreign Assets Control (OFAC) <a href="https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks">sanctioned the administrators of a rogue proxy network</a> called First VPN Service (1VPNS), aiming to cut off infrastructure used by ransomware operators. </p><p>While anyone shopping for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> expects privacy, First VPN actively courted cybercriminals with promises of total anonymity, leading <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">European law enforcement to pull the plug on the service</a> earlier in May.</p><p>As part of the new sanctions, the US Treasury published a list of web addresses associated with the VPN. Buried in that list was a link to First VPN's public Telegram support channel: t.me/FirstVPNService.</p><h2 id="a-sledgehammer-to-crack-a-nut">A sledgehammer to crack a nut</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qp6PFkub49CUBhgFaHwjeQ" name="First VPN" alt="This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, "This service has been seized"" src="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)</span></figcaption></figure><p>Because top-level domains operate under strict international compliance rules, domain registrars must act quickly when sanctioned entities use their infrastructure.</p><p>Identity Digital, the company managing the technical backend for the .me domain, <a href="https://meduza.io/en/news/2026/07/14/u-s-treasury-sanctions-on-a-vpn-service-knocked-out-telegram-s-short-link-domain-worldwide" target="_blank" rel="nofollow">confirmed that the t.me domain had been blocked</a> at the request of OFAC. </p><p>However, because a domain registry cannot selectively disable a specific webpage or channel path — like a single Telegram group — the Montenegro-based registry Domain.Me applied a "serverHold" status to Telegram's entire t.me domain.</p><p>This sweeping action effectively erased the domain from the global <a href="https://www.techradar.com/vpn/what-is-dns">Domain Name System (DNS)</a>. The core Telegram app continued to function, and the older telegram.me domain remained active, but the shortlinks the messaging platform is built upon went entirely dark.</p><h2 id="the-swift-resolution">The swift resolution</h2><p>The sudden shutdown prompted immediate action from Telegram's leadership. </p><p>Unaware of the backend domain hold, Telegram CEO Pavel Durov <a href="https://x.com/durov/status/2076836338117046660" target="_blank" rel="nofollow">took to X</a> to publicly ask the registrar for an explanation: "Hey @domainME, t.me links stopped working. Can you look into it?"</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2076836338117046660"><p lang="en" dir="ltr">Hey @domainME, https://t.co/9z6UC2o37U links stopped working. Can you look into it? 🙏<a href="https://twitter.com/cantworkitout/status/2076836338117046660">July 14, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Once the sanctions issue was identified, Telegram scrubbed the offending channels from its platform. The registry operator subsequently verified the compliance and brought the domain back online.</p><p>"On 13 July, 1VPNS was included as a sanctioned entity by the US Department of the Treasury. A Telegram channel using the t.me domain was among 1VPNS identified infrastructure. Accordingly, the t.me domain was suspended," domain.Me confirmed in a <a href="https://x.com/domainme/status/2077077395777994942" target="_blank" rel="nofollow">statement<u> </u></a>following the outage.</p><p>The registrar clarified that normal service resumed roughly a day later, after Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. "We appreciate Telegram's prompt cooperation in resolving this matter," domain.Me added.</p><p>While the outage is now resolved, the incident highlights a glaring vulnerability in the modern web, where a single URL swept up in a government sanctions list can inadvertently silence an essential communication channel for millions.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ First VPN administrators sanctioned by US Treasury over ransomware attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The US Treasury has sanctioned First VPN's administrator for aiding ransomware attacks on American infrastructure</strong></li><li><strong>Another suspect was targeted for selling "cryptors" that cloak malware from security systems</strong></li><li><strong>The move follows a May 2026 takedown by European law enforcement and the FBI that seized the VPN's infrastructure</strong></li></ul><p>The United States government has officially issued sanctions against the operators of a notorious virtual private network (VPN), escalating a global crackdown on digital infrastructure used to facilitate ransomware attacks.</p><p>On Monday (July 13), the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated First VPN Service (also known as 1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi, for abetting cybercriminals. The service, which has operated since 2014, was heavily favored by ransomware gangs targeting American hospitals, municipalities, and businesses.</p><p>While the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are designed to protect everyday consumer privacy, rogue networks like First VPN provided malicious actors with the tools to "hide the origins of their attacks, deploy malware, and manage exfiltrated data," according to a <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="nofollow">Treasury Department press release</a>.</p><p>As part of the same action, the Treasury also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national accused of selling "cryptors" to ransomware operators. </p><p>While Silayev is not directly affiliated with First VPN, his inclusion in the sanctions package highlights a broader strategy of targeting the entire cybercriminal supply chain. Cryptors are tools specifically built to disguise ransomware as harmless files, preventing security systems from detecting or deactivating the malware.</p><h2 id="a-haven-for-cybercriminals">A haven for cybercriminals</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:940px;"><p class="vanilla-image-block" style="padding-top:57.98%;"><img id="U3nMoaJ3iNrFx8Qwkwmw7d" name="Shutterstock_1050436496.jpg" alt="Code Skull" src="https://cdn.mos.cms.futurecdn.net/U3nMoaJ3iNrFx8Qwkwmw7d.jpg" mos="" align="middle" fullscreen="" width="940" height="545" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The US Treasury's latest move is an update to an ongoing international operation against First VPN. </p><p>In a massive <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">May 2026 takedown</a>, a coordinated effort led by European law enforcement agencies and the FBI successfully seized the service's website and server infrastructure.</p><p>Prior to the takedown, Rashevskyi aggressively marketed First VPN on dark web forums. To lure cybercriminals, he promised total anonymity and boasted that the network "does not keep logs of users' identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers".</p><p>According to the US Treasury, Rashevskyi went to great lengths to keep the operation running. He utilized false identities, such as "Maksim Sorin" and "Roman Chabanenko," to "buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers".</p><h2 id="disrupting-the-cybercriminal-ecosystem">Disrupting the cybercriminal ecosystem</h2><p>This latest wave of sanctions was coordinated alongside the United Kingdom's Foreign, Commonwealth & Development Office (FCDO) and carries severe consequences for the designated individuals.</p><p>Under the new sanctions, all property and interests belonging to Rashevskyi and Silayev within the US are blocked, and US citizens are strictly prohibited from engaging in any transactions with them. Beyond the immediate financial freeze, OFAC sanctions serve as a massive reputational blow designed to choke off future revenue streams.</p><p>By focusing on the service providers and tool suppliers who facilitate these attacks, rather than just the ransomware operators themselves, authorities are aiming to maximize their impact and disrupt multiple gangs at once.</p><p>"Under President Trump's leadership, Treasury is using every available tool to disrupt the cybercriminal ecosystem and protect the American people," said Gene Lange, who is performing the duties of the Under Secretary for Terrorism and Financial Intelligence. "We will continue targeting the actors who enable ransomware attacks against Americans and our critical infrastructure".</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Following a massive Europol takedown in May, the US Treasury has officially sanctioned the administrators behind First VPN, a service favored by ransomware groups to hide their tracks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xcqXWhLyXc3yCpMeVRFUCX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 09:39:52 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jul 2026 11:05:33 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Milman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Fred TANNEAU / AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:description>                                                            <media:text><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:text>
                                <media:title type="plain"><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury has sanctioned First VPN's administrator for aiding ransomware attacks on American infrastructure</strong></li><li><strong>Another suspect was targeted for selling "cryptors" that cloak malware from security systems</strong></li><li><strong>The move follows a May 2026 takedown by European law enforcement and the FBI that seized the VPN's infrastructure</strong></li></ul><p>The United States government has officially issued sanctions against the operators of a notorious virtual private network (VPN), escalating a global crackdown on digital infrastructure used to facilitate ransomware attacks.</p><p>On Monday (July 13), the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated First VPN Service (also known as 1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi, for abetting cybercriminals. The service, which has operated since 2014, was heavily favored by ransomware gangs targeting American hospitals, municipalities, and businesses.</p><p>While the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are designed to protect everyday consumer privacy, rogue networks like First VPN provided malicious actors with the tools to "hide the origins of their attacks, deploy malware, and manage exfiltrated data," according to a <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="nofollow">Treasury Department press release</a>.</p><p>As part of the same action, the Treasury also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national accused of selling "cryptors" to ransomware operators. </p><p>While Silayev is not directly affiliated with First VPN, his inclusion in the sanctions package highlights a broader strategy of targeting the entire cybercriminal supply chain. Cryptors are tools specifically built to disguise ransomware as harmless files, preventing security systems from detecting or deactivating the malware.</p><h2 id="a-haven-for-cybercriminals">A haven for cybercriminals</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:940px;"><p class="vanilla-image-block" style="padding-top:57.98%;"><img id="U3nMoaJ3iNrFx8Qwkwmw7d" name="Shutterstock_1050436496.jpg" alt="Code Skull" src="https://cdn.mos.cms.futurecdn.net/U3nMoaJ3iNrFx8Qwkwmw7d.jpg" mos="" align="middle" fullscreen="" width="940" height="545" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The US Treasury's latest move is an update to an ongoing international operation against First VPN. </p><p>In a massive <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">May 2026 takedown</a>, a coordinated effort led by European law enforcement agencies and the FBI successfully seized the service's website and server infrastructure.</p><p>Prior to the takedown, Rashevskyi aggressively marketed First VPN on dark web forums. To lure cybercriminals, he promised total anonymity and boasted that the network "does not keep logs of users' identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers".</p><p>According to the US Treasury, Rashevskyi went to great lengths to keep the operation running. He utilized false identities, such as "Maksim Sorin" and "Roman Chabanenko," to "buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers".</p><h2 id="disrupting-the-cybercriminal-ecosystem">Disrupting the cybercriminal ecosystem</h2><p>This latest wave of sanctions was coordinated alongside the United Kingdom's Foreign, Commonwealth & Development Office (FCDO) and carries severe consequences for the designated individuals.</p><p>Under the new sanctions, all property and interests belonging to Rashevskyi and Silayev within the US are blocked, and US citizens are strictly prohibited from engaging in any transactions with them. Beyond the immediate financial freeze, OFAC sanctions serve as a massive reputational blow designed to choke off future revenue streams.</p><p>By focusing on the service providers and tool suppliers who facilitate these attacks, rather than just the ransomware operators themselves, authorities are aiming to maximize their impact and disrupt multiple gangs at once.</p><p>"Under President Trump's leadership, Treasury is using every available tool to disrupt the cybercriminal ecosystem and protect the American people," said Gene Lange, who is performing the duties of the Under Secretary for Terrorism and Financial Intelligence. "We will continue targeting the actors who enable ransomware attacks against Americans and our critical infrastructure".</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Baby Boomers beat Gen Z in password hygiene, but both generations still don’t stick to the best practices — and many people are still using decades-old passwords that they made as kids ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NordPass study claims older generations are more likely to change passwords than younger generations</strong></li><li><strong>But younger users are more in tune with password storage services, preferring to use password managers over memory and writing them down</strong></li><li><strong>All generations are failing to adhere to the best practices when it comes to password hygiene</strong></li></ul><p>Many people may believe Gen Z are the best when it comes to adopting new tech, but a new study by <a href="https://nordpass.com/blog/password-decline-research/" target="_blank">NordPass</a> polling 7,861 respondents between the ages of 18-74 suggests that they might be the worst generation for password hygiene.</p><p>It’s not uncommon for people to pick a particular word or phrase as a password and alternate special characters, numbers, and capital letters to keep it ‘unique’, but this practice is weakened when the same central password is used for years—or even decades.</p><p>In fact, Gen Z has been found to be the generation least likely to change a password, while Baby Boomers are the most security-conscious, actively updating their passwords much more frequently.</p><h2 id="baby-boomers-value-security">Baby Boomers value security</h2><p>When breaking down the stats, NordPass found just 54% of respondents had changed their longest-standing password in the last 12 months. Those aged 18-24 were the least likely to say they had updated their password within the last year, while those in older brackets, particularly between 55-to-64, were the most likely to update their passwords.</p><p>But there is a further trend to be examined. While those in the older age brackets are more likely to update their passwords, they rely on memory or physically writing down their passwords for storage. And those in the younger, more tech-savvy age brackets were more likely to rely on browser-based password storage or third-party password managers.</p><p>Writing down passwords or relying on memory often leads to the reuse of passwords to keep them memorable and easy to type, increasing the risk that personal accounts could be breached in the event of a cyberattack. While the average number of password has dropped from 168 in 2024 to 120 in 2026, this still leaves the average person with a significant number of possibly reused passwords that could leak, potentially compromising every account they are used on.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1062px;"><p class="vanilla-image-block" style="padding-top:62.52%;"><img id="tyRwAMqY2pue95yY3VEbzR" name="infographics-password-decline" alt="A graph displaying the average password storage statistics with respondents from Australia, Canada, the UK, the US, France, Germany, Italy, and Spain, showing more people store passwords in a browser." src="https://cdn.mos.cms.futurecdn.net/tyRwAMqY2pue95yY3VEbzR.jpg" mos="" align="middle" fullscreen="" width="1062" height="664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordPass)</span></figcaption></figure><p>Opting for the convenience of a browser-based password manager also introduces additional risk, as these password vaults often aren’t subjected to the same security protocols as third-party <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager apps</a>. </p><p>In fact, another recent NordPass study highlighted that <a href="https://www.techradar.com/pro/security/password-reuse-only-sharpens-this-problem-browser-based-password-storage-isnt-as-safe-as-you-think-these-top-tips-from-the-experts-show-how-it-should-be-done" target="_blank">browser-based passwords are at a significantly higher chance of being leaked or stolen</a> thanks to malware, browser compromise, or physical access to the computer.</p><p>This is especially true for those using a browser-based password manager alongside a third-party app, because if the browser is compromised there is little you can do to protect your stored passwords.</p><p>“I’m fairly certain most internet users know they should immediately change a password that has been compromised,” said Karolis Arbaciauskas, head of product at cybersecurity company NordPass.</p><p>“So when people say they haven’t changed a password in years, either the password hasn’t been exposed, or they simply don’t know it has. I hate to be a bearer of bad news, but the second scenario is far more likely. Without tools to notify them when credentials appear in leaks or breaches, many users have passwords aging in the background while the risk grows.”</p><h2 id="how-to-keep-your-passwords-as-secure-as-possible">How to keep your passwords as secure as possible</h2><p>There are many ways to <a href="https://www.techradar.com/pro/security/coming-up-with-a-new-password-doesnt-have-to-be-hard-im-a-password-expert-and-these-are-my-5-top-tips-for-crafting-the-perfect-password">create a secure password</a>. These are my expert recommendations for maximizing your password security:</p><ul><li>Your password should be at least 15 characters long</li><li>Rather than relying on a memorable phrase or key date, use a string of random words such as the NIST example of ‘cassette-lava-baby’</li><li>Add in some random capitalization, numbers, and special characters, but avoid replacing certain letters with predictable special characters (such as ‘@’ for ‘a’, ‘$’ for ‘s’, and so on)</li><li>If you are forced to regularly change a password as many people are forced to do in the workplace, always use a new, unique password, rather than relying on ‘Summer12345’ followed by ‘Autumn12345’</li><li>Wherever possible, use an <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">authenticator app</a>. This can range from an app on your phone that you use to approve a login or a physical security key that you keep on your person. Many authenticators use phishing resistant passkeys that authenticate your login attempts by using your facial scan or a fingerprint</li><li>Use a password manager to store your passwords securely. They also add the benefit of being able to autofill your credentials for you</li><li>Use a credential exposure checking service such as <a href="https://haveibeenpwned.com/" target="_blank">Have I Been Pwned</a> to securely check if your email address or passwords have shown up in any dark web databases</li><li>Delete any online accounts you no longer use. If the service suffers a data breach, it could leak your username and password combination</li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/baby-boomers-beat-gen-z-in-password-hygiene-but-both-generations-still-dont-stick-to-the-best-practices-and-many-people-are-still-using-decades-old-passwords-that-they-made-as-kids</link>
                                                                            <description>
                            <![CDATA[ Baby Boomers are the most likely to frequently change passwords, but often rely on unsecure methods of storage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9x7M8jUKqaYHh5NJXopDLJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World Password Day]]></media:description>                                                            <media:text><![CDATA[World Password Day]]></media:text>
                                <media:title type="plain"><![CDATA[World Password Day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordPass study claims older generations are more likely to change passwords than younger generations</strong></li><li><strong>But younger users are more in tune with password storage services, preferring to use password managers over memory and writing them down</strong></li><li><strong>All generations are failing to adhere to the best practices when it comes to password hygiene</strong></li></ul><p>Many people may believe Gen Z are the best when it comes to adopting new tech, but a new study by <a href="https://nordpass.com/blog/password-decline-research/" target="_blank">NordPass</a> polling 7,861 respondents between the ages of 18-74 suggests that they might be the worst generation for password hygiene.</p><p>It’s not uncommon for people to pick a particular word or phrase as a password and alternate special characters, numbers, and capital letters to keep it ‘unique’, but this practice is weakened when the same central password is used for years—or even decades.</p><p>In fact, Gen Z has been found to be the generation least likely to change a password, while Baby Boomers are the most security-conscious, actively updating their passwords much more frequently.</p><h2 id="baby-boomers-value-security">Baby Boomers value security</h2><p>When breaking down the stats, NordPass found just 54% of respondents had changed their longest-standing password in the last 12 months. Those aged 18-24 were the least likely to say they had updated their password within the last year, while those in older brackets, particularly between 55-to-64, were the most likely to update their passwords.</p><p>But there is a further trend to be examined. While those in the older age brackets are more likely to update their passwords, they rely on memory or physically writing down their passwords for storage. And those in the younger, more tech-savvy age brackets were more likely to rely on browser-based password storage or third-party password managers.</p><p>Writing down passwords or relying on memory often leads to the reuse of passwords to keep them memorable and easy to type, increasing the risk that personal accounts could be breached in the event of a cyberattack. While the average number of password has dropped from 168 in 2024 to 120 in 2026, this still leaves the average person with a significant number of possibly reused passwords that could leak, potentially compromising every account they are used on.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1062px;"><p class="vanilla-image-block" style="padding-top:62.52%;"><img id="tyRwAMqY2pue95yY3VEbzR" name="infographics-password-decline" alt="A graph displaying the average password storage statistics with respondents from Australia, Canada, the UK, the US, France, Germany, Italy, and Spain, showing more people store passwords in a browser." src="https://cdn.mos.cms.futurecdn.net/tyRwAMqY2pue95yY3VEbzR.jpg" mos="" align="middle" fullscreen="" width="1062" height="664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordPass)</span></figcaption></figure><p>Opting for the convenience of a browser-based password manager also introduces additional risk, as these password vaults often aren’t subjected to the same security protocols as third-party <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager apps</a>. </p><p>In fact, another recent NordPass study highlighted that <a href="https://www.techradar.com/pro/security/password-reuse-only-sharpens-this-problem-browser-based-password-storage-isnt-as-safe-as-you-think-these-top-tips-from-the-experts-show-how-it-should-be-done" target="_blank">browser-based passwords are at a significantly higher chance of being leaked or stolen</a> thanks to malware, browser compromise, or physical access to the computer.</p><p>This is especially true for those using a browser-based password manager alongside a third-party app, because if the browser is compromised there is little you can do to protect your stored passwords.</p><p>“I’m fairly certain most internet users know they should immediately change a password that has been compromised,” said Karolis Arbaciauskas, head of product at cybersecurity company NordPass.</p><p>“So when people say they haven’t changed a password in years, either the password hasn’t been exposed, or they simply don’t know it has. I hate to be a bearer of bad news, but the second scenario is far more likely. Without tools to notify them when credentials appear in leaks or breaches, many users have passwords aging in the background while the risk grows.”</p><h2 id="how-to-keep-your-passwords-as-secure-as-possible">How to keep your passwords as secure as possible</h2><p>There are many ways to <a href="https://www.techradar.com/pro/security/coming-up-with-a-new-password-doesnt-have-to-be-hard-im-a-password-expert-and-these-are-my-5-top-tips-for-crafting-the-perfect-password">create a secure password</a>. These are my expert recommendations for maximizing your password security:</p><ul><li>Your password should be at least 15 characters long</li><li>Rather than relying on a memorable phrase or key date, use a string of random words such as the NIST example of ‘cassette-lava-baby’</li><li>Add in some random capitalization, numbers, and special characters, but avoid replacing certain letters with predictable special characters (such as ‘@’ for ‘a’, ‘$’ for ‘s’, and so on)</li><li>If you are forced to regularly change a password as many people are forced to do in the workplace, always use a new, unique password, rather than relying on ‘Summer12345’ followed by ‘Autumn12345’</li><li>Wherever possible, use an <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">authenticator app</a>. This can range from an app on your phone that you use to approve a login or a physical security key that you keep on your person. Many authenticators use phishing resistant passkeys that authenticate your login attempts by using your facial scan or a fingerprint</li><li>Use a password manager to store your passwords securely. They also add the benefit of being able to autofill your credentials for you</li><li>Use a credential exposure checking service such as <a href="https://haveibeenpwned.com/" target="_blank">Have I Been Pwned</a> to securely check if your email address or passwords have shown up in any dark web databases</li><li>Delete any online accounts you no longer use. If the service suffers a data breach, it could leak your username and password combination</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malaysia is cracking down on VPN misuse, but your VPN stays perfectly legal ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Malaysia beefs up action against VPN used to facilitate crimes</strong></li><li><strong>Misuse includes bypassing the new under-16 social media ban</strong></li><li><strong>Officials have stressed that owning or using a VPN is not an offence</strong></li></ul><p>Malaysia is set to take action if VPN are used to facilitate criminal activities or help residents bypass the new social media age limit. </p><p>According to <a href="https://www.thestar.com.my/news/nation/2026/07/02/govt-steps-up-measures-against-vpn-abuse-third-party-identities-in-online-child-protection" target="_blank" rel="nofollow">local reports</a>, Deputy Home Minister Datuk Seri Dr Shamsul Anuar Nasarah said the government is working closely with the Malaysian Communications and Multimedia Commission (MCMC) to counter VPNs and borrowed identities that are being used to slip past newly enforced social media age limits.</p><p>For the many people who reach for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services to protect their browsing, encrypt their traffic, or simply keep their data out of advertisers' hands, the reassuring takeaway is that the tool itself is not the target. What the authorities want to reach is the small share of activity where a VPN is used as a shield for something illegal.</p><h2 id="what-malaysia-actually-announced">What Malaysia actually announced</h2><p>The comments came during a question-and-answer session on cybercrime and age verification. Shamsul Anuar explained that police would draw on public complaints and their own investigations to identify cases where VPNs or identity-masking tools are being abused, and that such misuse could be treated as an added element of an offence.</p><p>He was clear that the crackdown is aimed at conduct, not software. The minister framed the effort as part of Malaysia's wider push to protect children online, pointing to a sharp rise in offences.</p><p>This sits on top of <a href="https://www.nbcnews.com/world/asia/malaysia-enforces-ban-social-media-accounts-children-younger-16-rcna347823" target="_blank" rel="nofollow">Malaysia's under-16 social media ban</a>, which took effect on 1 June 2026 under the Online Safety Act 2025. Large platforms including Facebook, Instagram, TikTok, and YouTube must now verify users' ages and block under-16s from registering, with non-compliance carrying penalties reported at up to RM10 million. </p><p>VPNs enter the picture because they are an obvious way to make it look as though a user is somewhere the rules do not apply. Age verification laws elsewhere, <a href="https://www.techradar.com/vpn/vpn-privacy-security/under-16s-social-media-ban-lands-in-australia">such as Australia</a> and <a href="https://www.techradar.com/news/live/uk-social-media-ban-june-2026">the UK</a>, have repeatedly triggered spikes in VPN sign-ups, with many often being adults looking to protect the sensitive documents these systems ask them to hand over.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div><h2 id="what-it-means-for-everyday-vpn-users">What it means for everyday VPN users</h2><p>For most people, this is not a reason to stop using a VPN, and it is not a ban in disguise. </p><p>Digital rights groups, however, have been sharply critical of the age-verification model underpinning the ban. </p><p><a href="https://www.article19.org/resources/malaysia-mandatory-age-verification-undermines-privacy-and-free-expression/" target="_blank" rel="nofollow">ARTICLE 19</a>, alongside local partners, has argued the measure was rushed, is disproportionate, and risks normalising surveillance while exposing people's identity documents and biometric data to misuse. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/malaysia-is-cracking-down-on-vpn-misuse-but-your-vpn-stays-perfectly-legal</link>
                                                                            <description>
                            <![CDATA[ Malaysia says it will act against VPNs used to facilitate crimes such as online scams and child exploitation, but ministers confirm that ordinary, lawful VPN use remains legal. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6XApHaMiryYgTkHuULA4yJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HqPrzKWLAnMS44eCiRPwW-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jul 2026 16:40:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/HqPrzKWLAnMS44eCiRPwW-1280-80.png">
                                                            <media:credit><![CDATA[Future + Sergio Amiti via Getty Images+ Photo by Jaap Arriens/NurPhoto via Getty Images  ]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Malaysian flag blowing in the wind on the left, VPN icon on smartphone on the right]]></media:text>
                                <media:title type="plain"><![CDATA[Malaysian flag blowing in the wind on the left, VPN icon on smartphone on the right]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HqPrzKWLAnMS44eCiRPwW-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Malaysia beefs up action against VPN used to facilitate crimes</strong></li><li><strong>Misuse includes bypassing the new under-16 social media ban</strong></li><li><strong>Officials have stressed that owning or using a VPN is not an offence</strong></li></ul><p>Malaysia is set to take action if VPN are used to facilitate criminal activities or help residents bypass the new social media age limit. </p><p>According to <a href="https://www.thestar.com.my/news/nation/2026/07/02/govt-steps-up-measures-against-vpn-abuse-third-party-identities-in-online-child-protection" target="_blank" rel="nofollow">local reports</a>, Deputy Home Minister Datuk Seri Dr Shamsul Anuar Nasarah said the government is working closely with the Malaysian Communications and Multimedia Commission (MCMC) to counter VPNs and borrowed identities that are being used to slip past newly enforced social media age limits.</p><p>For the many people who reach for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services to protect their browsing, encrypt their traffic, or simply keep their data out of advertisers' hands, the reassuring takeaway is that the tool itself is not the target. What the authorities want to reach is the small share of activity where a VPN is used as a shield for something illegal.</p><h2 id="what-malaysia-actually-announced">What Malaysia actually announced</h2><p>The comments came during a question-and-answer session on cybercrime and age verification. Shamsul Anuar explained that police would draw on public complaints and their own investigations to identify cases where VPNs or identity-masking tools are being abused, and that such misuse could be treated as an added element of an offence.</p><p>He was clear that the crackdown is aimed at conduct, not software. The minister framed the effort as part of Malaysia's wider push to protect children online, pointing to a sharp rise in offences.</p><p>This sits on top of <a href="https://www.nbcnews.com/world/asia/malaysia-enforces-ban-social-media-accounts-children-younger-16-rcna347823" target="_blank" rel="nofollow">Malaysia's under-16 social media ban</a>, which took effect on 1 June 2026 under the Online Safety Act 2025. Large platforms including Facebook, Instagram, TikTok, and YouTube must now verify users' ages and block under-16s from registering, with non-compliance carrying penalties reported at up to RM10 million. </p><p>VPNs enter the picture because they are an obvious way to make it look as though a user is somewhere the rules do not apply. Age verification laws elsewhere, <a href="https://www.techradar.com/vpn/vpn-privacy-security/under-16s-social-media-ban-lands-in-australia">such as Australia</a> and <a href="https://www.techradar.com/news/live/uk-social-media-ban-june-2026">the UK</a>, have repeatedly triggered spikes in VPN sign-ups, with many often being adults looking to protect the sensitive documents these systems ask them to hand over.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div><h2 id="what-it-means-for-everyday-vpn-users">What it means for everyday VPN users</h2><p>For most people, this is not a reason to stop using a VPN, and it is not a ban in disguise. </p><p>Digital rights groups, however, have been sharply critical of the age-verification model underpinning the ban. </p><p><a href="https://www.article19.org/resources/malaysia-mandatory-age-verification-undermines-privacy-and-free-expression/" target="_blank" rel="nofollow">ARTICLE 19</a>, alongside local partners, has argued the measure was rushed, is disproportionate, and risks normalising surveillance while exposing people's identity documents and biometric data to misuse. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 81 million login attempts hit Microsoft 365 accounts as hackers try password-spraying to force entry using stolen credentials and OAuth to bypass authentication ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A password-spraying attack successfully breached Microsoft 365 accounts</strong></li><li><strong>The hackers abused improperly configured conditional access policies to bypass MFA</strong></li><li><strong>Many organizations targeted had no MFA implemented</strong></li></ul><p>Hackers have used previously leaked credentials to target Microsoft 365 accounts in a password-spraying attack that resulted in over 81 million login attempts during a two-week period.</p><p>The attackers then abused the improperly implemented Conditional Access policies within the Resource Owner Password Credentials (ROPC) OAuth mechanism using Azure command-line interface (CLI), allowing the hackers to bypass authentication altogether when a matching username and password was discovered.</p><p>Cybersecurity company <a href="https://www.huntress.com/blog/lshiy-password-spray-attack" target="_blank">Huntress</a> observed the attack campaign as it targeted customers and noted that 78 Microsoft accounts across 64 organizations were compromised between June 12 and 26 2026.</p><h2 id="hackers-access-365-accounts-without-authentication">Hackers access 365 accounts without authentication</h2><p>The success of the attack ultimately came down to how well organizations had implemented Conditional Access policies relating to multi-factor authentication. </p><p>“Many of the compromised businesses had implemented multi-factor authentication (MFA) via a Conditional Access Policy (CAP), but the MFA was not configured to cover this specific flow that attackers used,” Huntress explained, referring to the exploitation of ROPC.</p><p>“ROPC is considered problematic for several reasons, but one of those reasons is that it doesn't offer support for modern auth flows like MFA or SSO. That means, as we saw in this campaign, ROPC sends the password straight to the /token endpoint with no interactive MFA prompt.”</p><p>Several of the organizations that were breached did not enforce an MFA policy at all, with others only applying MFA for specific user groups such as administrators. In other cases, a login attempt only required MFA when the traffic was coming from an untrusted location, meaning that MFA was not enforced if the connection was coming from a trusted IP address. Additionally, some organizations had only enforced MFA in report-only mode, meaning that the MFA policies were never actually applied.</p><p>In order to protect against attacks of this kind of attack, Huntress recommended the following mitigations:</p><ul><li>Organizations should implement MFA for All Users, All Cloud Apps, and All Client App types</li><li>The Azure CLI application should be restricted from use by non-admin users</li><li>Response to the attack should be made on credential validity, rather than spray volume</li></ul><p>Via <a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/81-million-login-attempts-hit-microsoft-365-accounts-as-hackers-try-password-spraying-to-force-entry-using-stolen-credentials-and-oauth-to-bypass-authentication</link>
                                                                            <description>
                            <![CDATA[ The attack abused misconfigured conditional access policies to bypass multi-factor authentication protections. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d8vfHgQqzay2L4VV6dTngh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A password-spraying attack successfully breached Microsoft 365 accounts</strong></li><li><strong>The hackers abused improperly configured conditional access policies to bypass MFA</strong></li><li><strong>Many organizations targeted had no MFA implemented</strong></li></ul><p>Hackers have used previously leaked credentials to target Microsoft 365 accounts in a password-spraying attack that resulted in over 81 million login attempts during a two-week period.</p><p>The attackers then abused the improperly implemented Conditional Access policies within the Resource Owner Password Credentials (ROPC) OAuth mechanism using Azure command-line interface (CLI), allowing the hackers to bypass authentication altogether when a matching username and password was discovered.</p><p>Cybersecurity company <a href="https://www.huntress.com/blog/lshiy-password-spray-attack" target="_blank">Huntress</a> observed the attack campaign as it targeted customers and noted that 78 Microsoft accounts across 64 organizations were compromised between June 12 and 26 2026.</p><h2 id="hackers-access-365-accounts-without-authentication">Hackers access 365 accounts without authentication</h2><p>The success of the attack ultimately came down to how well organizations had implemented Conditional Access policies relating to multi-factor authentication. </p><p>“Many of the compromised businesses had implemented multi-factor authentication (MFA) via a Conditional Access Policy (CAP), but the MFA was not configured to cover this specific flow that attackers used,” Huntress explained, referring to the exploitation of ROPC.</p><p>“ROPC is considered problematic for several reasons, but one of those reasons is that it doesn't offer support for modern auth flows like MFA or SSO. That means, as we saw in this campaign, ROPC sends the password straight to the /token endpoint with no interactive MFA prompt.”</p><p>Several of the organizations that were breached did not enforce an MFA policy at all, with others only applying MFA for specific user groups such as administrators. In other cases, a login attempt only required MFA when the traffic was coming from an untrusted location, meaning that MFA was not enforced if the connection was coming from a trusted IP address. Additionally, some organizations had only enforced MFA in report-only mode, meaning that the MFA policies were never actually applied.</p><p>In order to protect against attacks of this kind of attack, Huntress recommended the following mitigations:</p><ul><li>Organizations should implement MFA for All Users, All Cloud Apps, and All Client App types</li><li>The Azure CLI application should be restricted from use by non-admin users</li><li>Response to the attack should be made on credential validity, rather than spray volume</li></ul><p>Via <a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘100% of Hide My Email addresses were exploitable’: Apple’s security feature can be duped into supplying the real contact info — and the bug has remained unpatched for over a year ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Apple Hide My Email can reveal a user's authentic email address</strong></li><li><strong>The bug puts users at risk of identification, experts warned</strong></li><li><strong>It has been unpatched for over a year</strong></li></ul><p>A bug in Apple’s ‘Hide My Email’ feature allows for those with knowledge of the vulnerability to identify the real email address hidden behind the anonymous email address.</p><p>The bug was discovered by EasyOptOuts co-founder, Tyler Murphy, who shared the exploit with <a href="https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/" target="_blank"><em>404 Media</em></a> after notifying Apple multiple times that the feature could be actively exploited.</p><p>“We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer,” Murphy said.</p><h2 id="hide-my-email-can-be-actively-exploited">Hide My Email can be actively exploited</h2><p>As the bug still hasn’t been patched, the details of how the exploit works have not been shared. </p><p>Apple’s Hide My Email feature was designed to anonymize email addresses, helping to prevent a user’s real email address from being leaked in a data breach, or to prevent a user’s email address from being linked to them personally in a way that could reveal their identity.</p><p>There lies the crux of the issue. By being able to identify the real email address by exploiting the bug, a malicious actor could uncover the real identity of the anonymized email.</p><p>“Free, publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk,” Murphy said. “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”</p><p>Users concerned about being identified via people-search sites can use a <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data removal service</a> to have their data scrubbed from these sites, but the process can take a few days.</p><p>The issue was first reported to Apply by Murphy in June 2025, with Apple replying a month later that it was looking into the cause of the issue. Earlier this year, in March, Apple said that it had “addressed the reported issue in a recent system change,” but Murphy found that the bug could still be exploited.</p><p>Again, Murphy notified Apple, who replied in May 2026, stating, “We are still investigating this issue. To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete. We appreciate your assistance in helping us to maintain and improve the security of our products."</p><p>Later in the same month, Apply said a fix was “expected in the coming weeks."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/100-percent-of-hide-my-email-addresses-were-exploitable-apples-security-feature-can-be-duped-into-supplying-the-real-contact-info-and-the-bug-has-remained-unpatched-for-over-a-year</link>
                                                                            <description>
                            <![CDATA[ The bug was reported to Apple over a year ago, but still nothing has been done. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8zAuVdPwPxYpCY6BAjr9eN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 13:57:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple / 9to5Mac]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:description>                                                            <media:text><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple Hide My Email can reveal a user's authentic email address</strong></li><li><strong>The bug puts users at risk of identification, experts warned</strong></li><li><strong>It has been unpatched for over a year</strong></li></ul><p>A bug in Apple’s ‘Hide My Email’ feature allows for those with knowledge of the vulnerability to identify the real email address hidden behind the anonymous email address.</p><p>The bug was discovered by EasyOptOuts co-founder, Tyler Murphy, who shared the exploit with <a href="https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/" target="_blank"><em>404 Media</em></a> after notifying Apple multiple times that the feature could be actively exploited.</p><p>“We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer,” Murphy said.</p><h2 id="hide-my-email-can-be-actively-exploited">Hide My Email can be actively exploited</h2><p>As the bug still hasn’t been patched, the details of how the exploit works have not been shared. </p><p>Apple’s Hide My Email feature was designed to anonymize email addresses, helping to prevent a user’s real email address from being leaked in a data breach, or to prevent a user’s email address from being linked to them personally in a way that could reveal their identity.</p><p>There lies the crux of the issue. By being able to identify the real email address by exploiting the bug, a malicious actor could uncover the real identity of the anonymized email.</p><p>“Free, publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk,” Murphy said. “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”</p><p>Users concerned about being identified via people-search sites can use a <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data removal service</a> to have their data scrubbed from these sites, but the process can take a few days.</p><p>The issue was first reported to Apply by Murphy in June 2025, with Apple replying a month later that it was looking into the cause of the issue. Earlier this year, in March, Apple said that it had “addressed the reported issue in a recent system change,” but Murphy found that the bug could still be exploited.</p><p>Again, Murphy notified Apple, who replied in May 2026, stating, “We are still investigating this issue. To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete. We appreciate your assistance in helping us to maintain and improve the security of our products."</p><p>Later in the same month, Apply said a fix was “expected in the coming weeks."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nearly 400 illegal World Cup 2026 streaming sites taken offline by US DOJ ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US DOJ has seized nearly 400 domains</strong></li><li><strong>The sites were being used to illegally stream World Cup games</strong></li><li><strong>Users of the sites were exposed to malware, data theft, and other threats</strong></li></ul><p>Almost 400 domains have been seized as part of Operation Offsides - a coordinated global effort to take down sites illegally streaming the FIFA World Cup 2026.</p><p>The sites were seized by the US Justice Department's Criminal Division for violating copyright and intellectual property law.</p><p>The takedowns were coordinated by members of the International Computer Hacking and Intellectual Property (ICHIP) network.</p><h2 id="us-and-friends-enforce-the-offside-rule">US and friends enforce the offside rule</h2><p>Many of the seized domains now display a banner explaining that the website was seized as part of Operation Offsides. “This action was taken to protect consumers and enforce intellectual property rights worldwide,” the banner states.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:628px;"><p class="vanilla-image-block" style="padding-top:60.83%;"><img id="wSkc22iLD5oCmHtsdaH9MZ" name="seizure_banner_fifa_world_cup" alt="A screenshot of the banner uploaded to domains seized by the US DOJ that were illegal streaming 2026 FIFA World Cup games." src="https://cdn.mos.cms.futurecdn.net/wSkc22iLD5oCmHtsdaH9MZ.webp" mos="" align="middle" fullscreen="" width="628" height="382" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: U.S. Justice Department)</span></figcaption></figure><p>Back in May 2026, the FBI warned that thousands of domains were being registered ahead of the World Cup, with most set up with the intention to scam fans looking for cheap tickets, access to streaming services, and those looking for discounted merchandise. It appears that Operation Offside was focused on disrupting streaming sites in particular, rather than taking down the wider scam networks associated with these domains.</p><p>“We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division.</p><p>“This operation illustrates the Department’s respect for intellectual property rights and the responsibility of the United States as a host nation to protect the FIFA World Cup from criminals. The Criminal Division will continue to disrupt and, where appropriate, seek to prosecute these sites and the subjects responsible for this criminal activity.”</p><p>In many cases, the networks of fake domains offering cheap or free access to streaming services are run by cybercriminals deliberately operating at a loss in order to attract users to their services. In return for accessing the streaming site, the domain will use the user’s local network as an exit node for the cybercriminal network, obscuring their traffic and making it appear legitimate.</p><p>Unfortunately for the user, who may think they have just found <a href="https://www.techradar.com/how-to-watch/football/world-cup-2026-free-anywhere">free access to every World Cup game</a>, their network and IP address could be used to distribute malware, cybercriminal communications, and illegal content such as stolen data and exploitative materials - including child sex abuse material.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/nearly-400-illegal-world-cup-2026-streaming-sites-taken-offline-by-us-doj</link>
                                                                            <description>
                            <![CDATA[ Operation Offsides was a coordinated takedown of sites illegal streaming World Cup games. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bb9zwqtckkZobw2ECG6Aq6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2TTaVZdSSeLQizvYPKXnck-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 13:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Streaming]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2TTaVZdSSeLQizvYPKXnck-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Michael Regan - FIFA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FIFA World Cup 2026 in Washington DC]]></media:description>                                                            <media:text><![CDATA[FIFA World Cup 2026 in Washington DC]]></media:text>
                                <media:title type="plain"><![CDATA[FIFA World Cup 2026 in Washington DC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2TTaVZdSSeLQizvYPKXnck-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US DOJ has seized nearly 400 domains</strong></li><li><strong>The sites were being used to illegally stream World Cup games</strong></li><li><strong>Users of the sites were exposed to malware, data theft, and other threats</strong></li></ul><p>Almost 400 domains have been seized as part of Operation Offsides - a coordinated global effort to take down sites illegally streaming the FIFA World Cup 2026.</p><p>The sites were seized by the US Justice Department's Criminal Division for violating copyright and intellectual property law.</p><p>The takedowns were coordinated by members of the International Computer Hacking and Intellectual Property (ICHIP) network.</p><h2 id="us-and-friends-enforce-the-offside-rule">US and friends enforce the offside rule</h2><p>Many of the seized domains now display a banner explaining that the website was seized as part of Operation Offsides. “This action was taken to protect consumers and enforce intellectual property rights worldwide,” the banner states.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:628px;"><p class="vanilla-image-block" style="padding-top:60.83%;"><img id="wSkc22iLD5oCmHtsdaH9MZ" name="seizure_banner_fifa_world_cup" alt="A screenshot of the banner uploaded to domains seized by the US DOJ that were illegal streaming 2026 FIFA World Cup games." src="https://cdn.mos.cms.futurecdn.net/wSkc22iLD5oCmHtsdaH9MZ.webp" mos="" align="middle" fullscreen="" width="628" height="382" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: U.S. Justice Department)</span></figcaption></figure><p>Back in May 2026, the FBI warned that thousands of domains were being registered ahead of the World Cup, with most set up with the intention to scam fans looking for cheap tickets, access to streaming services, and those looking for discounted merchandise. It appears that Operation Offside was focused on disrupting streaming sites in particular, rather than taking down the wider scam networks associated with these domains.</p><p>“We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division.</p><p>“This operation illustrates the Department’s respect for intellectual property rights and the responsibility of the United States as a host nation to protect the FIFA World Cup from criminals. The Criminal Division will continue to disrupt and, where appropriate, seek to prosecute these sites and the subjects responsible for this criminal activity.”</p><p>In many cases, the networks of fake domains offering cheap or free access to streaming services are run by cybercriminals deliberately operating at a loss in order to attract users to their services. In return for accessing the streaming site, the domain will use the user’s local network as an exit node for the cybercriminal network, obscuring their traffic and making it appear legitimate.</p><p>Unfortunately for the user, who may think they have just found <a href="https://www.techradar.com/how-to-watch/football/world-cup-2026-free-anywhere">free access to every World Cup game</a>, their network and IP address could be used to distribute malware, cybercriminal communications, and illegal content such as stolen data and exploitative materials - including child sex abuse material.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI warns of Russian Intelligence phishing campaign abusing Signal support services to target VIPs and high-value government and military targets — this is how to secure your account ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Russian Intelligence are targeting Signal accounts of officials based in Ukraine</strong></li><li><strong>They pose as Signal support services and ask users to submit their Backup Recovery Keys</strong></li><li><strong>Using these keys, the hackers can hijack the users account and any other accounts created using the same mobile phone number</strong></li></ul><p>The FBI has warned Russian Intelligence Services are posing as commercial messaging application support services in order to steal Backup Recovery Keys belonging to targets of high value in the military and government of the US, Europe, and Ukraine.</p><p>In a <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank">joint warning</a> alongside the CISA and the Security Service of Ukraine (SSU), the FBI outlined the new phishing campaign which seeks to access messaging accounts in order to perform intelligence gathering of secret information.</p><p>Specifically, the FBI provided sample phishing lures targeting users of the Signal messaging app. If the hackers successfully lure a victim into sharing their Backup Recovery Key, they can access the account's message history, private and group messages, and fully take over the victim's account.</p><h2 id="russian-intelligence-pose-as-signal-support-services">Russian Intelligence pose as Signal support services</h2><p>In the FBI warning, the phishing techniques are further detailed. The Russian Federal Security Service (FSB) are targeting government officials, military personnel, political figures, journalists, and key officials from the US and Europe located in Ukraine.</p><p>The attackers send emails that appear to be automated messages from Signal, asking users to turn on their message backup using their Backup Recovery Key. Victims are provided with false instructions that instead send the Backup Recovery Key to the attacker, who can then use the key to take over the victim’s account.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:777px;"><p class="vanilla-image-block" style="padding-top:108.62%;"><img id="JoZ4UqwN8LL25f5u4bEqvH" name="Screenshot 2026-06-29 131941" alt="Example phishing messages used by Russian Intelligence, supplied by the FBI" src="https://cdn.mos.cms.futurecdn.net/JoZ4UqwN8LL25f5u4bEqvH.png" mos="" align="middle" fullscreen="" width="777" height="844" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Example phishing messages used by Russian Intelligence to obtain Backup Recovery Keys </span><span class="credit" itemprop="copyrightHolder">(Image credit: FBI)</span></figcaption></figure><p>In order to establish urgency and trust that the message is legitimate, the attackers posed the phishing message as a protection against recent hacking attempts from “Iran and post-Soviet countries.” In another sample message, the attacker's message says that the victim’s account data “is at risk of permanent loss due to a sync issue.”</p><p>If a victim shares their unique Backup Recovery Key, it allows the attacker to hijack their current Signal account alongside any subsequent accounts made with the same phone number.</p><p>For users who may fear their Backup Recovery Key has been compromised, users are instructed to use Signal settings to create a new Backup Recovery Key. This new key will invalidate all previous Backup Recovery Keys and prevent account takeover if the previous key was leaked.</p><p>In order to avoid falling victim to phishing messages, there are several ways to stay safe:</p><ul><li>Support services will generally only communicate with users via an official company email address. Always carefully check communications from the legitimate email address.</li><li>Customer support will never request that you supply your Backup Recovery Key via the application</li><li>You will never be asked to verify or restore your account via an automated customer support message</li></ul><p>In order to further protect your Signal account, or other accounts, against phishing, users should consider the following:</p><ul><li>Use a passkey wherever possible. This will use your device’s built in biometric verification methods to authenticate your login.</li><li>Use phishing resistant multi-factor authentication where possible</li><li>Always double check messages and emails are legitimate, and are using an official company email</li><li>Never supply your Backup Recovery Keys unless you are actively attempting to regain access to your account via a legitimate service</li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-warns-of-russian-intelligence-phishing-campaign-abusing-signal-support-services-to-target-vips-and-high-value-government-and-military-targets-this-is-how-to-secure-your-account</link>
                                                                            <description>
                            <![CDATA[ Russian Intelligence are trying to hijack Signal accounts by tricking users into sending their Backup Recovery Keys ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NFHSVuh7G9qYjTamC5fMmJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zjaJ25xrgFNLKEHr8bjVcY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 18:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Email & Messaging]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zjaJ25xrgFNLKEHr8bjVcY-1280-80.jpg">
                                                            <media:credit><![CDATA[Michele Ursi / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WhatsApp and Signal app icons]]></media:description>                                                            <media:text><![CDATA[WhatsApp and Signal app icons]]></media:text>
                                <media:title type="plain"><![CDATA[WhatsApp and Signal app icons]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zjaJ25xrgFNLKEHr8bjVcY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian Intelligence are targeting Signal accounts of officials based in Ukraine</strong></li><li><strong>They pose as Signal support services and ask users to submit their Backup Recovery Keys</strong></li><li><strong>Using these keys, the hackers can hijack the users account and any other accounts created using the same mobile phone number</strong></li></ul><p>The FBI has warned Russian Intelligence Services are posing as commercial messaging application support services in order to steal Backup Recovery Keys belonging to targets of high value in the military and government of the US, Europe, and Ukraine.</p><p>In a <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank">joint warning</a> alongside the CISA and the Security Service of Ukraine (SSU), the FBI outlined the new phishing campaign which seeks to access messaging accounts in order to perform intelligence gathering of secret information.</p><p>Specifically, the FBI provided sample phishing lures targeting users of the Signal messaging app. If the hackers successfully lure a victim into sharing their Backup Recovery Key, they can access the account's message history, private and group messages, and fully take over the victim's account.</p><h2 id="russian-intelligence-pose-as-signal-support-services">Russian Intelligence pose as Signal support services</h2><p>In the FBI warning, the phishing techniques are further detailed. The Russian Federal Security Service (FSB) are targeting government officials, military personnel, political figures, journalists, and key officials from the US and Europe located in Ukraine.</p><p>The attackers send emails that appear to be automated messages from Signal, asking users to turn on their message backup using their Backup Recovery Key. Victims are provided with false instructions that instead send the Backup Recovery Key to the attacker, who can then use the key to take over the victim’s account.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:777px;"><p class="vanilla-image-block" style="padding-top:108.62%;"><img id="JoZ4UqwN8LL25f5u4bEqvH" name="Screenshot 2026-06-29 131941" alt="Example phishing messages used by Russian Intelligence, supplied by the FBI" src="https://cdn.mos.cms.futurecdn.net/JoZ4UqwN8LL25f5u4bEqvH.png" mos="" align="middle" fullscreen="" width="777" height="844" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Example phishing messages used by Russian Intelligence to obtain Backup Recovery Keys </span><span class="credit" itemprop="copyrightHolder">(Image credit: FBI)</span></figcaption></figure><p>In order to establish urgency and trust that the message is legitimate, the attackers posed the phishing message as a protection against recent hacking attempts from “Iran and post-Soviet countries.” In another sample message, the attacker's message says that the victim’s account data “is at risk of permanent loss due to a sync issue.”</p><p>If a victim shares their unique Backup Recovery Key, it allows the attacker to hijack their current Signal account alongside any subsequent accounts made with the same phone number.</p><p>For users who may fear their Backup Recovery Key has been compromised, users are instructed to use Signal settings to create a new Backup Recovery Key. This new key will invalidate all previous Backup Recovery Keys and prevent account takeover if the previous key was leaked.</p><p>In order to avoid falling victim to phishing messages, there are several ways to stay safe:</p><ul><li>Support services will generally only communicate with users via an official company email address. Always carefully check communications from the legitimate email address.</li><li>Customer support will never request that you supply your Backup Recovery Key via the application</li><li>You will never be asked to verify or restore your account via an automated customer support message</li></ul><p>In order to further protect your Signal account, or other accounts, against phishing, users should consider the following:</p><ul><li>Use a passkey wherever possible. This will use your device’s built in biometric verification methods to authenticate your login.</li><li>Use phishing resistant multi-factor authentication where possible</li><li>Always double check messages and emails are legitimate, and are using an official company email</li><li>Never supply your Backup Recovery Keys unless you are actively attempting to regain access to your account via a legitimate service</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 14 million login credentials leaked from six ISPs in major data breach — here’s what we know ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Tens of millions of credentials may have been leaked following an attack on one of Japan's largest ISPs</strong></li><li><strong>The attack leveraged a vulnerability in a third-party software used by KDDI</strong></li><li><strong>Five other ISPs were also affected in the attack</strong></li></ul><p>A data breach that has potentially exposed the email and password combinations for over 14 million customers across six internet service providers (ISPs) has been disclosed by Japanese telecoms provider KDDI Corporation.</p><p>According to the company, hackers exploited a vulnerability in a third-party software to access the database of credentials. KDDI said that it immediately blocked the hackers' access after discovering the intrusion on June 17, 2026.</p><p>“Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” the company said in a <a href="https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-71_4593/kddi_nr_s-71_4593_pdf_01.pdf" target="_blank" rel="nofollow">statement</a>.</p><h2 id="millions-of-credentials-exposed">Millions of credentials exposed</h2><p>Unfortunately, the breach was not confined to just KDDI. The email services of five other ISPs were also affected by the breach:</p><ul><li>STNet, Inc.</li><li>JCOM Co., Ltd.</li><li>Chubu Telecommunications C., Inc.</li><li>NIFTY Corporation</li><li>BIGLOBE Inc.</li></ul><p>KDDI is yet to finish a formal investigation into the attack, but said that the hacker may have gained access to the emails addresses and passwords for 14.22 million current and former customers. The company also said that some of the passwords were stored in an encrypted format, and so will be inaccessible for the hackers, but the company did not say how many were stored in this manner.</p><p>Since discovering the breach, KDDI has also been working alongside the affected ISPs to secure systems and put in place mitigation measures to counter the abuse of exposed account credentials.</p><p>In order to stay protected, customers have been advised to change their account passwords and implement two-factor authentication.</p><p>Breaches such as these are particularly dangerous because they expose email and password combinations. As most people will have either one or two email addresses across their accounts, it increases the likelihood that hackers can attempt to use the exposed email and password combinations to try and access other accounts created with the same email.</p><p>This is especially true if the same password (or a variant thereof) is used across multiple accounts. Hackers can use brute force techniques to try hundreds of password combinations in a very short amount of time in order to crack weak or reused passwords.</p><p>When creating or updating a password for any account, no matter how infrequently it is used, always create a strong unique password. <a href="https://www.techradar.com/best/password-manager" target="_blank">Password managers</a> can create and suggest strong passwords, securely store them, and automatically fill login forms to take the hassle out of remembering passwords. </p><p>Alternatively, some services offer the ability to login using a <a href="https://www.techradar.com/pro/passwords-out-passkeys-in-the-future-of-secure-authentication" target="_blank">passkey</a>, which utilizes the built-in biometric authentication mechanisms of your device such as a facial scan or fingerprint. These login methods not only remove the need to type in passwords, but also reduce the possibility of hackers accessing your account through phishing attacks.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/over-14-million-login-credentials-leaked-from-six-isps-in-major-data-breach-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ The credentials were exposed via an attack on third-party software. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q3LqdS6SNsXmNzrsX9V2tX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 17:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Email & Messaging]]></category>
                                                    <category><![CDATA[Software & Services]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Tens of millions of credentials may have been leaked following an attack on one of Japan's largest ISPs</strong></li><li><strong>The attack leveraged a vulnerability in a third-party software used by KDDI</strong></li><li><strong>Five other ISPs were also affected in the attack</strong></li></ul><p>A data breach that has potentially exposed the email and password combinations for over 14 million customers across six internet service providers (ISPs) has been disclosed by Japanese telecoms provider KDDI Corporation.</p><p>According to the company, hackers exploited a vulnerability in a third-party software to access the database of credentials. KDDI said that it immediately blocked the hackers' access after discovering the intrusion on June 17, 2026.</p><p>“Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” the company said in a <a href="https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-71_4593/kddi_nr_s-71_4593_pdf_01.pdf" target="_blank" rel="nofollow">statement</a>.</p><h2 id="millions-of-credentials-exposed">Millions of credentials exposed</h2><p>Unfortunately, the breach was not confined to just KDDI. The email services of five other ISPs were also affected by the breach:</p><ul><li>STNet, Inc.</li><li>JCOM Co., Ltd.</li><li>Chubu Telecommunications C., Inc.</li><li>NIFTY Corporation</li><li>BIGLOBE Inc.</li></ul><p>KDDI is yet to finish a formal investigation into the attack, but said that the hacker may have gained access to the emails addresses and passwords for 14.22 million current and former customers. The company also said that some of the passwords were stored in an encrypted format, and so will be inaccessible for the hackers, but the company did not say how many were stored in this manner.</p><p>Since discovering the breach, KDDI has also been working alongside the affected ISPs to secure systems and put in place mitigation measures to counter the abuse of exposed account credentials.</p><p>In order to stay protected, customers have been advised to change their account passwords and implement two-factor authentication.</p><p>Breaches such as these are particularly dangerous because they expose email and password combinations. As most people will have either one or two email addresses across their accounts, it increases the likelihood that hackers can attempt to use the exposed email and password combinations to try and access other accounts created with the same email.</p><p>This is especially true if the same password (or a variant thereof) is used across multiple accounts. Hackers can use brute force techniques to try hundreds of password combinations in a very short amount of time in order to crack weak or reused passwords.</p><p>When creating or updating a password for any account, no matter how infrequently it is used, always create a strong unique password. <a href="https://www.techradar.com/best/password-manager" target="_blank">Password managers</a> can create and suggest strong passwords, securely store them, and automatically fill login forms to take the hassle out of remembering passwords. </p><p>Alternatively, some services offer the ability to login using a <a href="https://www.techradar.com/pro/passwords-out-passkeys-in-the-future-of-secure-authentication" target="_blank">passkey</a>, which utilizes the built-in biometric authentication mechanisms of your device such as a facial scan or fingerprint. These login methods not only remove the need to type in passwords, but also reduce the possibility of hackers accessing your account through phishing attacks.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out — that income tax form could actually be dangerous malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Fake tax notices are becoming delivery vehicles for sophisticated remote access malware</strong></li><li><strong>Attackers hide malicious code behind convincing government branding and legal references</strong></li><li><strong>The malware quietly establishes encrypted communication with servers outside the country</strong></li></ul><p>A new phishing campaign is using fake income tax assessment notices to deliver dangerous malware to unsuspecting victims across India.</p><p>Researchers at <a href="https://www.cyfirma.com/research/an-income-tax-assessment-notice-phishing-campaign-delivering-malware/" target="_blank">CYFIRMA</a> identified the operation, which relies on a fraudulent website built to resemble official communication from the Indian Income Tax Department closely.</p><p>The fake portal, hosted on a recently registered domain, presents a convincing assessment order complete with legal references, financial penalties, and urgent compliance language designed to pressure recipients into acting quickly.</p><h2 id="how-the-infection-unfolds">How the infection unfolds</h2><p>Victims who interact with the fake notice are prompted to download a ZIP archive disguised as official assessment documentation and supporting calculations.</p><p>Once extracted, that archive reveals a disk image file functioning as a container for the actual malicious payload.</p><p>Inside sits a loader program that quietly triggers a second component, a DLL file disguised to resemble a legitimate Windows service.</p><p>Researchers found that this loader uses reflection-based techniques specifically built to make automated detection and analysis considerably more difficult.</p><p>Both files were obfuscated using a known protection tool, further complicating efforts by security teams to inspect the code.</p><p>Once active, the payload behaves like a Remote Access Trojan, granting attackers persistent, encrypted access to the infected machine.</p><p>It can collect system details, monitor user activity, check which security software is installed, and silently load additional malicious components on command.</p><p>Communication with the attacker's server happens over an encrypted channel, using a hardcoded address traced to infrastructure based in Hong Kong.</p><p>These capabilities point toward a financially motivated operation, rather than one focused on immediate damage or disruption, and they closely resemble traits associated with known commodity RAT families such as XWorm.</p><p>However, researchers note that conclusive attribution to a specific threat actor remains unconfirmed at this stage.</p><h2 id="why-this-campaign-matters">Why this campaign matters</h2><p>This is not an isolated phishing attempt but part of a broader pattern of attackers exploiting tax season anxiety to bypass user caution entirely.</p><p>CYFIRMA's findings show the same loader-and-payload architecture has previously been linked to <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> operators, suggesting this infrastructure may serve more than one type of attack depending on the victim.</p><p>Up-to-date <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> with behavioral detection remains one practical defence against this kind of staged, multi-component <a href="https://www.techradar.com/best/best-malware-removal">malware</a> delivery.</p><p>Security researchers recommend that individuals verify any tax-related correspondence directly through official government channels rather than clicking embedded links.</p><p>Organizations are advised to restrict the execution of unknown files arriving through archives or disk images, since this campaign relies heavily on that exact delivery method to succeed.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-that-income-tax-form-could-actually-be-dangerous-malware</link>
                                                                            <description>
                            <![CDATA[ Researchers uncovered a fake tax notice campaign that delivered remote-access malware via staged downloads and encrypted communications. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qR5LQKebhB7ovBuobVQom</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 28 Jun 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1280-80.jpg">
                                                            <media:credit><![CDATA[financialcrimeacademy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Income tax fraud]]></media:description>                                                            <media:text><![CDATA[Income tax fraud]]></media:text>
                                <media:title type="plain"><![CDATA[Income tax fraud]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fake tax notices are becoming delivery vehicles for sophisticated remote access malware</strong></li><li><strong>Attackers hide malicious code behind convincing government branding and legal references</strong></li><li><strong>The malware quietly establishes encrypted communication with servers outside the country</strong></li></ul><p>A new phishing campaign is using fake income tax assessment notices to deliver dangerous malware to unsuspecting victims across India.</p><p>Researchers at <a href="https://www.cyfirma.com/research/an-income-tax-assessment-notice-phishing-campaign-delivering-malware/" target="_blank">CYFIRMA</a> identified the operation, which relies on a fraudulent website built to resemble official communication from the Indian Income Tax Department closely.</p><p>The fake portal, hosted on a recently registered domain, presents a convincing assessment order complete with legal references, financial penalties, and urgent compliance language designed to pressure recipients into acting quickly.</p><h2 id="how-the-infection-unfolds">How the infection unfolds</h2><p>Victims who interact with the fake notice are prompted to download a ZIP archive disguised as official assessment documentation and supporting calculations.</p><p>Once extracted, that archive reveals a disk image file functioning as a container for the actual malicious payload.</p><p>Inside sits a loader program that quietly triggers a second component, a DLL file disguised to resemble a legitimate Windows service.</p><p>Researchers found that this loader uses reflection-based techniques specifically built to make automated detection and analysis considerably more difficult.</p><p>Both files were obfuscated using a known protection tool, further complicating efforts by security teams to inspect the code.</p><p>Once active, the payload behaves like a Remote Access Trojan, granting attackers persistent, encrypted access to the infected machine.</p><p>It can collect system details, monitor user activity, check which security software is installed, and silently load additional malicious components on command.</p><p>Communication with the attacker's server happens over an encrypted channel, using a hardcoded address traced to infrastructure based in Hong Kong.</p><p>These capabilities point toward a financially motivated operation, rather than one focused on immediate damage or disruption, and they closely resemble traits associated with known commodity RAT families such as XWorm.</p><p>However, researchers note that conclusive attribution to a specific threat actor remains unconfirmed at this stage.</p><h2 id="why-this-campaign-matters">Why this campaign matters</h2><p>This is not an isolated phishing attempt but part of a broader pattern of attackers exploiting tax season anxiety to bypass user caution entirely.</p><p>CYFIRMA's findings show the same loader-and-payload architecture has previously been linked to <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> operators, suggesting this infrastructure may serve more than one type of attack depending on the victim.</p><p>Up-to-date <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> with behavioral detection remains one practical defence against this kind of staged, multi-component <a href="https://www.techradar.com/best/best-malware-removal">malware</a> delivery.</p><p>Security researchers recommend that individuals verify any tax-related correspondence directly through official government channels rather than clicking embedded links.</p><p>Organizations are advised to restrict the execution of unknown files arriving through archives or disk images, since this campaign relies heavily on that exact delivery method to succeed.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GTA VI fans beware — experts warn 'a new wave of scam websites' is offering early access, but just stealing your bank details instead ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Fake GTA VI beta keys are already draining cryptocurrency wallets worldwide</strong></li><li><strong>AI-generated scam websites now imitate Rockstar branding with alarming accuracy</strong></li><li><strong>Malware hidden inside fake game downloads can expose banking credentials instantly</strong></li></ul><p>Grand Theft Auto VI is not due on consoles until November 19 2026, but official preorders open soon, and cybersecurity researchers have warned criminals are already exploiting the wait with a coordinated wave of fraudulent websites.</p><p>Malwarebytes and NordVPN have both flagged sites promising "VIP early access" or exclusive beta keys to one of gaming's most anticipated releases.</p><p>The schemes ask victims to hand over money, personal information, or both, often before any real product changes hands.</p><h2 id="how-the-scam-works">How the scam works</h2><p>Some fraudulent sites ask players to pay a few hundred dollars in cryptocurrency for a so-called VIP beta key. This method makes refunds or fraud reports practically impossible once the payment clears.</p><p>According to Stefan Dasic of Malwarebytes, GTA VI is "the perfect bait" that can be used by cybercriminals.</p><p>The franchise sold hundreds of millions of copies and went 13 years without a new entry — conditions that make hype, and therefore impatience, unusually intense.</p><p>Gerald Kasulis of NordVPN said scammers now use AI to mimic Rockstar's official branding so convincingly that polished emails and websites slip past a gamer's usual scepticism.</p><p>Some pages invoke the phrase "help us build Vice City," a reference to the game's fictional setting, to create a false sense of insider access.</p><p>Victims are sometimes directed to download software branded as an early build, including one fake file called GTA Mobile 6.</p><p>According to researchers, this file contains <a href="https://www.techradar.com/best/best-malware-removal">malware</a> capable of letting fraudsters remotely access the victim's device, often bypassing <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> software.</p><p>NordVPN has separately traced some of these fraudulent domains to a wider network with a documented history of spreading banking trojans, infostealers, and <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Other variants simply harvest names, addresses, dates of birth, or existing GTA login credentials, data that can then be resold.</p><p>Several of these scam sites even target PC and Android users, despite Rockstar never confirming that those versions exist yet.</p><h2 id="who-is-being-targeted">Who is being targeted?</h2><p>The typical victim tends to be someone too young, too eager, or simply underinformed, and primarily driven by a desire to be first in line for the game.</p><p>However, Malwarebytes' assessment of the scam wave reveals that the trick itself is rarely sophisticated, yet it consistently fools people regardless of age.</p><p>The character of those falling for these scams goes beyond simple naivety, since urgency and curiosity are what scammers are really exploiting across these campaigns.</p><p>Younger players and newcomers to online gaming appear especially exposed, given their relative unfamiliarity with how official preorder and beta access processes normally function.</p><p>Neither company has data on exactly how many people have visited these sites or lost money so far.</p><p>Rockstar Games has not responded to requests for comment on the ongoing scam wave or its impact on players.</p><p>Security researchers are urging anyone tempted by claims of early GTA VI access to pause and verify the source before entering any personal or financial details.</p><p>Players who have already entered credentials or payment information are advised to change their passwords immediately.</p><p>They should also contact their bank without delay, since cryptocurrency payments in particular cannot be reversed once sent. </p><p>Via <a href="https://www.pcgamer.com/games/grand-theft-auto/grand-theft-auto-6-vip-early-access-scam-sites-are-already-popping-up-malwarebytes-warns/" target="_blank" rel="nofollow">PCGAMER</a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/gta-vi-fans-beware-experts-warn-a-new-wave-of-scam-websites-is-offering-early-access-but-just-stealing-your-bank-details-instead</link>
                                                                            <description>
                            <![CDATA[ Cybercriminals are exploiting GTA VI anticipation with fake beta programmes designed to steal money, credentials, and personal information. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RkCkYdUg2ZHeUHU4pa3vaS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EweZxK8eSVuvCSALvxaDL5-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sat, 27 Jun 2026 23:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/EweZxK8eSVuvCSALvxaDL5-1280-80.png">
                                                            <media:credit><![CDATA[Malwarebytes]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA VI fake websites are now everywhere — be warned]]></media:description>                                                            <media:text><![CDATA[GTA VI fake websites are now everywhere — be warned]]></media:text>
                                <media:title type="plain"><![CDATA[GTA VI fake websites are now everywhere — be warned]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EweZxK8eSVuvCSALvxaDL5-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fake GTA VI beta keys are already draining cryptocurrency wallets worldwide</strong></li><li><strong>AI-generated scam websites now imitate Rockstar branding with alarming accuracy</strong></li><li><strong>Malware hidden inside fake game downloads can expose banking credentials instantly</strong></li></ul><p>Grand Theft Auto VI is not due on consoles until November 19 2026, but official preorders open soon, and cybersecurity researchers have warned criminals are already exploiting the wait with a coordinated wave of fraudulent websites.</p><p>Malwarebytes and NordVPN have both flagged sites promising "VIP early access" or exclusive beta keys to one of gaming's most anticipated releases.</p><p>The schemes ask victims to hand over money, personal information, or both, often before any real product changes hands.</p><h2 id="how-the-scam-works">How the scam works</h2><p>Some fraudulent sites ask players to pay a few hundred dollars in cryptocurrency for a so-called VIP beta key. This method makes refunds or fraud reports practically impossible once the payment clears.</p><p>According to Stefan Dasic of Malwarebytes, GTA VI is "the perfect bait" that can be used by cybercriminals.</p><p>The franchise sold hundreds of millions of copies and went 13 years without a new entry — conditions that make hype, and therefore impatience, unusually intense.</p><p>Gerald Kasulis of NordVPN said scammers now use AI to mimic Rockstar's official branding so convincingly that polished emails and websites slip past a gamer's usual scepticism.</p><p>Some pages invoke the phrase "help us build Vice City," a reference to the game's fictional setting, to create a false sense of insider access.</p><p>Victims are sometimes directed to download software branded as an early build, including one fake file called GTA Mobile 6.</p><p>According to researchers, this file contains <a href="https://www.techradar.com/best/best-malware-removal">malware</a> capable of letting fraudsters remotely access the victim's device, often bypassing <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> software.</p><p>NordVPN has separately traced some of these fraudulent domains to a wider network with a documented history of spreading banking trojans, infostealers, and <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Other variants simply harvest names, addresses, dates of birth, or existing GTA login credentials, data that can then be resold.</p><p>Several of these scam sites even target PC and Android users, despite Rockstar never confirming that those versions exist yet.</p><h2 id="who-is-being-targeted">Who is being targeted?</h2><p>The typical victim tends to be someone too young, too eager, or simply underinformed, and primarily driven by a desire to be first in line for the game.</p><p>However, Malwarebytes' assessment of the scam wave reveals that the trick itself is rarely sophisticated, yet it consistently fools people regardless of age.</p><p>The character of those falling for these scams goes beyond simple naivety, since urgency and curiosity are what scammers are really exploiting across these campaigns.</p><p>Younger players and newcomers to online gaming appear especially exposed, given their relative unfamiliarity with how official preorder and beta access processes normally function.</p><p>Neither company has data on exactly how many people have visited these sites or lost money so far.</p><p>Rockstar Games has not responded to requests for comment on the ongoing scam wave or its impact on players.</p><p>Security researchers are urging anyone tempted by claims of early GTA VI access to pause and verify the source before entering any personal or financial details.</p><p>Players who have already entered credentials or payment information are advised to change their passwords immediately.</p><p>They should also contact their bank without delay, since cryptocurrency payments in particular cannot be reversed once sent. </p><p>Via <a href="https://www.pcgamer.com/games/grand-theft-auto/grand-theft-auto-6-vip-early-access-scam-sites-are-already-popping-up-malwarebytes-warns/" target="_blank" rel="nofollow">PCGAMER</a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Unnamed hackers steal stolen data from Icarus hackers responsible for Klue supply chain hack — and yes, it's as confusing as it sounds ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Klue recently suffered a cyber attack at the hands of Icarus</strong></li><li><strong>Icarus was apparently deleting the stolen customer data</strong></li><li><strong>An unnamed group claims to have stolen the data from Icarus, and is now extorting Klue customers directly</strong></li></ul><p>Earlier this month, market research provider Klue suffered a cyberattack with the knock-on effects <a href="https://www.techradar.com/pro/security/lastpass-confirms-data-breach-after-hacker-compromises-supply-chain-heres-what-we-know" target="_blank">hitting major companies such as LastPass</a>, Gong, Jamf, HackerOne, Huntress and others.</p><p>Klue has since revealed it is in contact with the Icarus ransomware group, who claim to have been in possession of stolen data and were threatening to leak the data in an attempt to extort the company.</p><p>But a second, unnamed group has emerged, which claims to have broken into a member of the Icarus group’s environment to steal the customer data stolen by Icarus from Klue. This second group is now apparently attempting to extort Klue customers directly, much to the annoyance of Icarus.</p><h2 id="hackers-hacked-by-hackers">Hackers hacked by hackers</h2><p>An update shared privately with Klue customers on Wednesday night and seen by <a href="https://techcrunch.com/2026/06/25/hacked-klue-says-criminals-are-deleting-stolen-customer-data-but-now-other-hackers-are-making-threats/" target="_blank"><em>TechCrunch</em></a> said, “We continue to communicate with the threat actor we have been in contact with (‘Icarus’). Icarus told us they are taking steps to delete the data taken from Klue customers. The Icarus site remains down and we have indications that Icarus is indeed taking steps to delete data taken from Klue customers.”</p><p>Icarus later informed Klue that the second group was attempting to extort Klue customers using the same data, having posted a list of affected companies on its own website. Alongside this list, they also claimed to have stolen the customer data from Icarus, after one of the Icarus group accidentally allowed the group to connect to the server hosting the stolen data.</p><p>Although there is no evidence that Klue has paid the Icarus group, the unnamed group also posted a statement that an “Icarus operator who is a teenager living somewhere in the UK or adjacent countries” had been paid by Klue to delete the stolen data.</p><p>A further communique issued by Klue to its customers said that it had been reassured by Icarus that the unnamed group only had samples of the stolen data, not the full set. It also said that, “Icarus has asked us to inform Klue customers to not make payment to this other party.”</p><p>Klue also suggested that its customers should ask the second group for random samples of their data to prove whether or not they actually had obtained the full set of stolen customer data.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/unnamed-hackers-steal-stolen-data-from-icarus-hackers-responsible-for-klue-supply-chain-hack-and-yes-its-as-confusing-as-it-sounds</link>
                                                                            <description>
                            <![CDATA[ Klue was hacked by Icarus, and then Icarus was hacked by another group. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dn5yZH8XeXT5eSKjpEMKUe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 13:27:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Klue recently suffered a cyber attack at the hands of Icarus</strong></li><li><strong>Icarus was apparently deleting the stolen customer data</strong></li><li><strong>An unnamed group claims to have stolen the data from Icarus, and is now extorting Klue customers directly</strong></li></ul><p>Earlier this month, market research provider Klue suffered a cyberattack with the knock-on effects <a href="https://www.techradar.com/pro/security/lastpass-confirms-data-breach-after-hacker-compromises-supply-chain-heres-what-we-know" target="_blank">hitting major companies such as LastPass</a>, Gong, Jamf, HackerOne, Huntress and others.</p><p>Klue has since revealed it is in contact with the Icarus ransomware group, who claim to have been in possession of stolen data and were threatening to leak the data in an attempt to extort the company.</p><p>But a second, unnamed group has emerged, which claims to have broken into a member of the Icarus group’s environment to steal the customer data stolen by Icarus from Klue. This second group is now apparently attempting to extort Klue customers directly, much to the annoyance of Icarus.</p><h2 id="hackers-hacked-by-hackers">Hackers hacked by hackers</h2><p>An update shared privately with Klue customers on Wednesday night and seen by <a href="https://techcrunch.com/2026/06/25/hacked-klue-says-criminals-are-deleting-stolen-customer-data-but-now-other-hackers-are-making-threats/" target="_blank"><em>TechCrunch</em></a> said, “We continue to communicate with the threat actor we have been in contact with (‘Icarus’). Icarus told us they are taking steps to delete the data taken from Klue customers. The Icarus site remains down and we have indications that Icarus is indeed taking steps to delete data taken from Klue customers.”</p><p>Icarus later informed Klue that the second group was attempting to extort Klue customers using the same data, having posted a list of affected companies on its own website. Alongside this list, they also claimed to have stolen the customer data from Icarus, after one of the Icarus group accidentally allowed the group to connect to the server hosting the stolen data.</p><p>Although there is no evidence that Klue has paid the Icarus group, the unnamed group also posted a statement that an “Icarus operator who is a teenager living somewhere in the UK or adjacent countries” had been paid by Klue to delete the stolen data.</p><p>A further communique issued by Klue to its customers said that it had been reassured by Icarus that the unnamed group only had samples of the stolen data, not the full set. It also said that, “Icarus has asked us to inform Klue customers to not make payment to this other party.”</p><p>Klue also suggested that its customers should ask the second group for random samples of their data to prove whether or not they actually had obtained the full set of stolen customer data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Travelers are getting better at spotting obvious scams' — but experts warn Airbnb scams are on the rise as summer arrives ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Airbnb scams have surged 30x since 2023, including a sharp rise this year</strong></li><li><strong>Criminals hijack legitimate host accounts to to trick holidaymakers</strong></li><li><strong>Staying safe isn't so straightforward as threats evolve</strong></li></ul><p>Airbnb-related scam activity has increased 30x since the first half of 2023, according to new research from Saily and NordStellar, confirming that cybercriminals continue to go after holidaymakers seeking the best deals amid rising prices.</p><p>The report ultimately concludes that attackers are now targeting the trust built by larger platforms, saving them from having to build new identities from scratch.</p><p>And to top it all off, the nature of scams is also changing, as instead of using suspicious websites to obtain victim payments or information, criminals are now targeting legitimate Airbnb host accounts which have spent years amassing positive reviews and high ratings.</p><h2 id="exploiting-legitimate-accounts-and-hijacking-trust">Exploiting legitimate accounts and hijacking trust</h2><p>While the end goal remains high volumes of vulnerable consumers, scammers have added an extra layer of victim in their pipeline. Verified Airbnb hosts are now valuable assets for criminals because they already have identity verifications, positive reviews, booking histories, years of activity and established credibility.</p><p>Once the verified account is compromised, attackers can then go on to scam higher volumes of unsuspecting victims by posting – and charging for – fake property listings.</p><p>“Travelers are getting better at spotting obvious scams,” Saily Head of Product Matas Cenys said. “Criminals know this, so they are increasingly trying to steal trust instead of building fake trust from scratch.”</p><p>Where this type of attack differs from others, though, is that the victims never leave the platform. Rather than falling victim to phishing attacks and being redirected to malicious external sites, they interact fully with supposed legitimate hosts on the Airbnb platform.</p><p>While Airbnb attacks have seen a 30x increase in around three years and a sharp rise in the last year alone, they reflect a much broader trend of attackers compromising existing trusted accounts.</p><p>The recent ramp-up in attacks could also be tied to the summer season, with holidaymakers looking to book last-minute deals in the run-up to the summer season. Urgency and pressure to keep costs low also adds to criminals’ success.</p><p>“Everything looks normal until they arrive at their destination and discover the accommodation never existed," Cenys added.</p><h2 id="how-to-protect-yourself-from-booking-scams">How to protect yourself from booking scams</h2><p>Saily is recommending that all communication stays within the booking platform and that customers avoid payment methods suggested outside of official channels. Unusually attractive listings in high-demand destinations could also be taken with a pinch of salt, and savvy shoppers may choose to reverse image search a property to double check its authenticity.</p><p>“As travel booking becomes increasingly digital, trust becomes one of the most valuable currencies in the travel ecosystem,” Cenys warned.</p><p>As for abusing victim trust, researchers also argue that AI has aided attacks by allowing criminals to produce better fake listings more quickly.</p><p>More generally, Airbnb revealed that two in five Americans have fallen victim for an online scam, with the average loss totalling nearly $2,000. The company has introduced measures to remind its users how to avoid scams, including introducing identity verification and reminders not to leave the platform, but account takeovers can still slip under the radar.</p><p>Airbnb also holds guest payments until 24 hours after check-in to ensure that everything is as described. Anti-fraud tech also prevented around 265,000 suspicious listings from appearing on the platform in 2025, the company boasted.</p><p>The company <a href="https://news.airbnb.com/partnering-with-experts-on-tips-to-help-avoid-summer-travel-scams-in-u-s/" target="_blank">posted</a> a comprehensive eight-step list of how to avoid scams on its platform online, calling out pressure tactics and unusual deals.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/travelers-are-getting-better-at-spotting-obvious-scams-but-experts-warn-airbnb-scams-are-on-the-rise-as-summer-arrives</link>
                                                                            <description>
                            <![CDATA[ As summer travel peaks, experts warn of Airbnb scams exploiting verified host accounts to trick users into fake vacations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7XmXUDBXn3r3R4jkjMNZ8j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TTY5Kw4XBVMnVyegXQfgGT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Jun 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TTY5Kw4XBVMnVyegXQfgGT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Iryna Kalamurza]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Young couple planning honeymoon vacation trip with map]]></media:description>                                                            <media:text><![CDATA[Young couple planning honeymoon vacation trip with map]]></media:text>
                                <media:title type="plain"><![CDATA[Young couple planning honeymoon vacation trip with map]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TTY5Kw4XBVMnVyegXQfgGT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Airbnb scams have surged 30x since 2023, including a sharp rise this year</strong></li><li><strong>Criminals hijack legitimate host accounts to to trick holidaymakers</strong></li><li><strong>Staying safe isn't so straightforward as threats evolve</strong></li></ul><p>Airbnb-related scam activity has increased 30x since the first half of 2023, according to new research from Saily and NordStellar, confirming that cybercriminals continue to go after holidaymakers seeking the best deals amid rising prices.</p><p>The report ultimately concludes that attackers are now targeting the trust built by larger platforms, saving them from having to build new identities from scratch.</p><p>And to top it all off, the nature of scams is also changing, as instead of using suspicious websites to obtain victim payments or information, criminals are now targeting legitimate Airbnb host accounts which have spent years amassing positive reviews and high ratings.</p><h2 id="exploiting-legitimate-accounts-and-hijacking-trust">Exploiting legitimate accounts and hijacking trust</h2><p>While the end goal remains high volumes of vulnerable consumers, scammers have added an extra layer of victim in their pipeline. Verified Airbnb hosts are now valuable assets for criminals because they already have identity verifications, positive reviews, booking histories, years of activity and established credibility.</p><p>Once the verified account is compromised, attackers can then go on to scam higher volumes of unsuspecting victims by posting – and charging for – fake property listings.</p><p>“Travelers are getting better at spotting obvious scams,” Saily Head of Product Matas Cenys said. “Criminals know this, so they are increasingly trying to steal trust instead of building fake trust from scratch.”</p><p>Where this type of attack differs from others, though, is that the victims never leave the platform. Rather than falling victim to phishing attacks and being redirected to malicious external sites, they interact fully with supposed legitimate hosts on the Airbnb platform.</p><p>While Airbnb attacks have seen a 30x increase in around three years and a sharp rise in the last year alone, they reflect a much broader trend of attackers compromising existing trusted accounts.</p><p>The recent ramp-up in attacks could also be tied to the summer season, with holidaymakers looking to book last-minute deals in the run-up to the summer season. Urgency and pressure to keep costs low also adds to criminals’ success.</p><p>“Everything looks normal until they arrive at their destination and discover the accommodation never existed," Cenys added.</p><h2 id="how-to-protect-yourself-from-booking-scams">How to protect yourself from booking scams</h2><p>Saily is recommending that all communication stays within the booking platform and that customers avoid payment methods suggested outside of official channels. Unusually attractive listings in high-demand destinations could also be taken with a pinch of salt, and savvy shoppers may choose to reverse image search a property to double check its authenticity.</p><p>“As travel booking becomes increasingly digital, trust becomes one of the most valuable currencies in the travel ecosystem,” Cenys warned.</p><p>As for abusing victim trust, researchers also argue that AI has aided attacks by allowing criminals to produce better fake listings more quickly.</p><p>More generally, Airbnb revealed that two in five Americans have fallen victim for an online scam, with the average loss totalling nearly $2,000. The company has introduced measures to remind its users how to avoid scams, including introducing identity verification and reminders not to leave the platform, but account takeovers can still slip under the radar.</p><p>Airbnb also holds guest payments until 24 hours after check-in to ensure that everything is as described. Anti-fraud tech also prevented around 265,000 suspicious listings from appearing on the platform in 2025, the company boasted.</p><p>The company <a href="https://news.airbnb.com/partnering-with-experts-on-tips-to-help-avoid-summer-travel-scams-in-u-s/" target="_blank">posted</a> a comprehensive eight-step list of how to avoid scams on its platform online, calling out pressure tactics and unusual deals.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A newbie hacker used "vague, low-skill prompts" in Claude and Codex to breach 14 companies, and the AI Agents did all the legwork ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OALABS analyzed a novice attacker’s full working directory showing 14 breaches carried out with Claude Code and Codex agents</strong></li><li><strong>Attacker used vague prompts; AI agents handled reconnaissance, exploit writing, and data harvesting, bypassing guardrails with ease</strong></li><li><strong>Logs revealed attacker’s identity and location in Addis Ababa, Ethiopia</strong></li></ul><p>A newbie cybercriminal managed to break into 14 organizations and steal sensitive data, just by using Anthropic’s Claude Code and OpenAI’s Codex agents. This is according to cybersecurity researchers OALABS, who recovered and analyzed the attacker’s entire working directory.</p><p>The researchers used this news as yet another proof that advanced Generative Artificial Intelligence (<a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GenAI</a>) models are significantly lowering the barrier for entry into cybercrime, and to sound the alarm that the security community needs to step up.</p><p>“In many cases, the attacker supplied only vague, low-skill prompts and allowed Claude to fill in the gaps: researching exposed services, identifying possible vulnerabilities, writing exploit code, validating access, and harvesting data,” the researchers said. “The attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts. The agent supplied much of the structure and technical execution that the attacker appeared to lack.”</p><h2 id="doxxing-the-attacker">Doxxing the attacker</h2><p>OALABS could not find evidence that the stolen data was monetized in any way, either by being sold on the dark web, or by extorting the victim companies. They did, however, find numerous pieces of evidence about the attacker’s identity and whereabouts.</p><p>According to the researchers, the attacker did not run the AI agents on his own infrastructure, but rather on a third-party server, and when that third party discovered malicious activity, they downloaded the entire working directory and shared it with the researchers.</p><p>“Because the agents were local to the host, their full session logs were recovered, including the attacker’s prompts, the tools used, the internal monologue of the large language model (LLM), and any policy violations recorded during the sessions,” the researchers said.</p><p>OALABS was thus able to analyze more than 1,000 agent sessions, seeing how the attacker was able, with ease, to bypass most of the agents’ guardrails. Among the sessions were also the threat actor’s CV with his full name, location, education history, and LinkedIn profile, as well as his IP address which showed that he was located in Addis Ababa, Ethiopia.</p><p><em>Via </em><a href="https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/" target="_blank"><em>Helpnet Security</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-newbie-hacker-used-vague-low-skill-prompts-in-claude-and-codex-to-breach-14-companies-and-the-ai-agents-did-all-the-legwork</link>
                                                                            <description>
                            <![CDATA[ A newbie hacker is still a newbie hacker, though, and this one left a few gaping holes in his work. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VMRSV9yYEZbm4Lkvnzczmn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:description>                                                            <media:text><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:text>
                                <media:title type="plain"><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OALABS analyzed a novice attacker’s full working directory showing 14 breaches carried out with Claude Code and Codex agents</strong></li><li><strong>Attacker used vague prompts; AI agents handled reconnaissance, exploit writing, and data harvesting, bypassing guardrails with ease</strong></li><li><strong>Logs revealed attacker’s identity and location in Addis Ababa, Ethiopia</strong></li></ul><p>A newbie cybercriminal managed to break into 14 organizations and steal sensitive data, just by using Anthropic’s Claude Code and OpenAI’s Codex agents. This is according to cybersecurity researchers OALABS, who recovered and analyzed the attacker’s entire working directory.</p><p>The researchers used this news as yet another proof that advanced Generative Artificial Intelligence (<a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GenAI</a>) models are significantly lowering the barrier for entry into cybercrime, and to sound the alarm that the security community needs to step up.</p><p>“In many cases, the attacker supplied only vague, low-skill prompts and allowed Claude to fill in the gaps: researching exposed services, identifying possible vulnerabilities, writing exploit code, validating access, and harvesting data,” the researchers said. “The attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts. The agent supplied much of the structure and technical execution that the attacker appeared to lack.”</p><h2 id="doxxing-the-attacker">Doxxing the attacker</h2><p>OALABS could not find evidence that the stolen data was monetized in any way, either by being sold on the dark web, or by extorting the victim companies. They did, however, find numerous pieces of evidence about the attacker’s identity and whereabouts.</p><p>According to the researchers, the attacker did not run the AI agents on his own infrastructure, but rather on a third-party server, and when that third party discovered malicious activity, they downloaded the entire working directory and shared it with the researchers.</p><p>“Because the agents were local to the host, their full session logs were recovered, including the attacker’s prompts, the tools used, the internal monologue of the large language model (LLM), and any policy violations recorded during the sessions,” the researchers said.</p><p>OALABS was thus able to analyze more than 1,000 agent sessions, seeing how the attacker was able, with ease, to bypass most of the agents’ guardrails. Among the sessions were also the threat actor’s CV with his full name, location, education history, and LinkedIn profile, as well as his IP address which showed that he was located in Addis Ababa, Ethiopia.</p><p><em>Via </em><a href="https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/" target="_blank"><em>Helpnet Security</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘I barely slept last night’: Hackers sent an ‘extreme’ alert to millions of Brazilians using the government’s own tools, and that’s a huge concern ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Millions of Brazilians received an unauthorized government alert</strong></li><li><strong>The text simply read ‘misanthropi4’ and it’s unknown who sent it</strong></li><li><strong>The government has denied it was responsible, pointing towards hackers</strong></li></ul><p>If you’re based in the US, you might know about AMBER alerts, also known as <a href="https://www.techradar.com/phones/android/your-android-phone-just-got-better-at-saving-your-life-heres-how">Wireless Emergency Alerts</a>, which are mass-broadcast messages sent to every <a href="https://www.techradar.com/news/best-phone">smartphone</a> in a designated area. Several other nations have similar platforms in place, including Brazil — but many Brazilians recently learned that their emergency alert system wasn’t quite as secure as they might have hoped.</p><p>In the early hours of Saturday morning, millions of Brazilians were jolted awake by a mysterious message from the country’s alert system. The alert level was classified as “extreme,” and concerningly, it’s thought it was the work of <a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know">hackers</a> rather than any official body. </p><p>The message, which was sent to civilians in the southern state of Paraná and the cities of São Paulo and Rio de Janeiro, among others, simply read “misantropi4.” That’s an approximation of the Portuguese word “misanthropia,” (with the final A swapped for a 4). As with the English word “misanthropy,” it means a hatred or distrust of humanity. </p><p>The message was accompanied by a loud alarm sound normally reserved for particularly severe thunderstorms. Since the text was sent shortly after midnight local time, it ensured that many people were woken up in the middle of the night. </p><p>Brazilian authorities said that the emergency message system was taken offline after a probable hacker attack, suggesting that this was more than just a simple text sent out in error by the government. Indeed, there was no event or natural disaster serious enough to warrant the alert being activated at the time, which further points towards bad actors being responsible.</p><h2 id="a-potentially-devastating-attack">A potentially devastating attack</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:738px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="3yJ4ZzG7h8cwpxdMsAJVqf" name="Brazil hackers alert system by BrazilianSwainSimp" alt="An alert sent by hackers to users in Brazil." src="https://cdn.mos.cms.futurecdn.net/3yJ4ZzG7h8cwpxdMsAJVqf.jpg" mos="" align="middle" fullscreen="" width="738" height="415" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">An example of the text sent by hackers to Brazilian civilians. </span><span class="credit" itemprop="copyrightHolder">(Image credit: BrazilianSwainSimp on Reddit)</span></figcaption></figure><p>The fact that hackers were able to breach a government system that has the potential to communicate with every mobile device in a given area of the country has worrying implications, both for the ways civilians could be manipulated and for the security of government institutions as a whole. </p><p>A text from a known government source is likely to be trusted more than one from an unknown number. With access to Brazil’s emergency broadcast system, hackers could potentially send out fraudulent messages that might have a larger impact than normal. That opens the door for all kinds of nefarious activities. </p><p>For now, this attack seems to have had a relatively minor impact. For many Brazilians posting on social media, the text was confusing more than anything else. </p><p><a href="https://www.reddit.com/r/mildlyinfuriating/comments/1uay1mi/comment/ossr3lj/" target="_blank">Last-Educator3947 on Reddit</a>, for example, said “I live in the town where the alert was first sent. It happened five minutes after the Brazil x Haiti <a href="https://www.techradar.com/how-to-watch/football/world-cup-2026-free">World Cup</a> game. My anxious brain associated misanthropy with a violent attack on the people celebrating in the streets after the game. I thought it was an incel <a href="https://www.techradar.com/computing/social-media/discord-just-made-your-voice-and-video-calls-more-private-and-secure-than-ever-but-age-verification-privacy-concerns-havent-been-dispelled">Discord</a> hacker sending a message to start a ‘The Purge’-style attack.” They then added: “I’m laughing now but I barely slept last night.” </p><p>Reddit user <a href="https://www.reddit.com/r/mildlyinfuriating/comments/1uay1mi/comment/osrt6os/" target="_blank">Magnon</a>, meanwhile, summed up the situation by saying that it, “Sounds like an anime villain just spawned.” </p><p>According to the <a href="https://x.com/IntCyberDigest/status/2068633434591830290" target="_blank">International Cyber Digest newsletter</a> on X, this breach could be linked to a previous hack of a Brazilian government employee who was infected with an <a href="https://www.techradar.com/pro/security/mac-users-beware-this-devious-new-infostealer-malware-disguises-itself-as-official-apple-tools-to-lure-in-victims">infostealer</a>. International Cyber Digest claims that stolen credentials included government logins, emails, developmental and staging environments, and more. </p><p>Whether or not this is what gave hackers access to the Brazilian government’s alert system isn’t yet known. Either way, it demonstrates the power that hackers can accrue if they find a way into supposedly secure governmental systems. While this alert saga turned out to be relatively harmless, that might not be the case next time.</p><div data-widget-type="multimodelreview" data-model-name="Apple iPhone 17,Apple iPhone 17 Pro,Apple iPhone 17 Pro Max,Apple iPhone 17e,Apple iPhone Air" data-widget-title="Today’s best iPhone deals"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/cyber-security/i-barely-slept-last-night-hackers-sent-an-extreme-alert-to-millions-of-brazilians-using-the-governments-own-tools-and-thats-a-huge-concern</link>
                                                                            <description>
                            <![CDATA[ Hackers breached government systems in Brazil to send millions of people a mysterious ‘extreme’ alert. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xzHZArtxfXsF9o77iA4yhc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ui7eDjrVhqovuAQCCWrpkF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 11:56:22 +0000</pubDate>                                                                                                                                <updated>Mon, 22 Jun 2026 11:59:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ui7eDjrVhqovuAQCCWrpkF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two hands holding a phone showing the Brazil flag and X]]></media:description>                                                            <media:text><![CDATA[Two hands holding a phone showing the Brazil flag and X]]></media:text>
                                <media:title type="plain"><![CDATA[Two hands holding a phone showing the Brazil flag and X]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ui7eDjrVhqovuAQCCWrpkF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Millions of Brazilians received an unauthorized government alert</strong></li><li><strong>The text simply read ‘misanthropi4’ and it’s unknown who sent it</strong></li><li><strong>The government has denied it was responsible, pointing towards hackers</strong></li></ul><p>If you’re based in the US, you might know about AMBER alerts, also known as <a href="https://www.techradar.com/phones/android/your-android-phone-just-got-better-at-saving-your-life-heres-how">Wireless Emergency Alerts</a>, which are mass-broadcast messages sent to every <a href="https://www.techradar.com/news/best-phone">smartphone</a> in a designated area. Several other nations have similar platforms in place, including Brazil — but many Brazilians recently learned that their emergency alert system wasn’t quite as secure as they might have hoped.</p><p>In the early hours of Saturday morning, millions of Brazilians were jolted awake by a mysterious message from the country’s alert system. The alert level was classified as “extreme,” and concerningly, it’s thought it was the work of <a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know">hackers</a> rather than any official body. </p><p>The message, which was sent to civilians in the southern state of Paraná and the cities of São Paulo and Rio de Janeiro, among others, simply read “misantropi4.” That’s an approximation of the Portuguese word “misanthropia,” (with the final A swapped for a 4). As with the English word “misanthropy,” it means a hatred or distrust of humanity. </p><p>The message was accompanied by a loud alarm sound normally reserved for particularly severe thunderstorms. Since the text was sent shortly after midnight local time, it ensured that many people were woken up in the middle of the night. </p><p>Brazilian authorities said that the emergency message system was taken offline after a probable hacker attack, suggesting that this was more than just a simple text sent out in error by the government. Indeed, there was no event or natural disaster serious enough to warrant the alert being activated at the time, which further points towards bad actors being responsible.</p><h2 id="a-potentially-devastating-attack">A potentially devastating attack</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:738px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="3yJ4ZzG7h8cwpxdMsAJVqf" name="Brazil hackers alert system by BrazilianSwainSimp" alt="An alert sent by hackers to users in Brazil." src="https://cdn.mos.cms.futurecdn.net/3yJ4ZzG7h8cwpxdMsAJVqf.jpg" mos="" align="middle" fullscreen="" width="738" height="415" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">An example of the text sent by hackers to Brazilian civilians. </span><span class="credit" itemprop="copyrightHolder">(Image credit: BrazilianSwainSimp on Reddit)</span></figcaption></figure><p>The fact that hackers were able to breach a government system that has the potential to communicate with every mobile device in a given area of the country has worrying implications, both for the ways civilians could be manipulated and for the security of government institutions as a whole. </p><p>A text from a known government source is likely to be trusted more than one from an unknown number. With access to Brazil’s emergency broadcast system, hackers could potentially send out fraudulent messages that might have a larger impact than normal. That opens the door for all kinds of nefarious activities. </p><p>For now, this attack seems to have had a relatively minor impact. For many Brazilians posting on social media, the text was confusing more than anything else. </p><p><a href="https://www.reddit.com/r/mildlyinfuriating/comments/1uay1mi/comment/ossr3lj/" target="_blank">Last-Educator3947 on Reddit</a>, for example, said “I live in the town where the alert was first sent. It happened five minutes after the Brazil x Haiti <a href="https://www.techradar.com/how-to-watch/football/world-cup-2026-free">World Cup</a> game. My anxious brain associated misanthropy with a violent attack on the people celebrating in the streets after the game. I thought it was an incel <a href="https://www.techradar.com/computing/social-media/discord-just-made-your-voice-and-video-calls-more-private-and-secure-than-ever-but-age-verification-privacy-concerns-havent-been-dispelled">Discord</a> hacker sending a message to start a ‘The Purge’-style attack.” They then added: “I’m laughing now but I barely slept last night.” </p><p>Reddit user <a href="https://www.reddit.com/r/mildlyinfuriating/comments/1uay1mi/comment/osrt6os/" target="_blank">Magnon</a>, meanwhile, summed up the situation by saying that it, “Sounds like an anime villain just spawned.” </p><p>According to the <a href="https://x.com/IntCyberDigest/status/2068633434591830290" target="_blank">International Cyber Digest newsletter</a> on X, this breach could be linked to a previous hack of a Brazilian government employee who was infected with an <a href="https://www.techradar.com/pro/security/mac-users-beware-this-devious-new-infostealer-malware-disguises-itself-as-official-apple-tools-to-lure-in-victims">infostealer</a>. International Cyber Digest claims that stolen credentials included government logins, emails, developmental and staging environments, and more. </p><p>Whether or not this is what gave hackers access to the Brazilian government’s alert system isn’t yet known. Either way, it demonstrates the power that hackers can accrue if they find a way into supposedly secure governmental systems. While this alert saga turned out to be relatively harmless, that might not be the case next time.</p><div data-widget-type="multimodelreview" data-model-name="Apple iPhone 17,Apple iPhone 17 Pro,Apple iPhone 17 Pro Max,Apple iPhone 17e,Apple iPhone Air" data-widget-title="Today’s best iPhone deals"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Simply being aware is no longer sufficient protection' — Security experts warn of AI-boosted scam campaigns that can trick even the smartest victims ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Nearly two-thirds of victims believe AI tools enabled their fraud experience</strong></li><li><strong>One in ten victims handed over money within just five minutes</strong></li><li><strong>Scammers moved across multiple platforms in 63% of incidents</strong></li></ul><p>Messaging scams are becoming increasingly sophisticated as criminals use AI to imitate trusted people, familiar brands, and everyday conversations.</p><p>New <a href="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2026/05/27050022/The_Great_Messaging_Heist_Report_2026_by_Kaspersky.pdf?kaspr=x75y" target="_blank" rel="nofollow">research</a> from Kaspersky suggests these schemes are succeeding with alarming speed, often convincing victims to hand over money within minutes.</p><p>The findings indicate that digital experience alone may no longer provide reliable protection against modern fraud attempts.</p><h2 id="ai-powered-scams-are-becoming-faster-and-more-convincing">AI-powered scams are becoming faster and more convincing</h2><p>The study found that nearly two-thirds of scam victims globally, or 64.5%, believed <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> played a role in the fraud attempts directed at them.</p><p>In the United Kingdom, 54% of respondents suspected criminals used deepfakes or synthetic voices to impersonate relatives, friends, or legitimate organizations, allowing scammers to create convincing scenarios that closely resemble genuine interactions and trusted relationships.</p><p>According to the research, more than half of UK victims completed payments or shared sensitive information within 30 minutes of initial contact.</p><p>More than 1 in 10 victims, representing 12.2%, did so within 5 minutes, demonstrating how rapidly these operations unfold.</p><p>Researchers also found nearly two-thirds (63%) of incidents moved across multiple communication platforms, helping fraudsters maintain credibility while avoiding suspicion.</p><p>The most common scams involved investment opportunities, affecting 40% of respondents, followed by fake delivery alert at 38% and brand impersonation schemes at 35%.</p><p>Dr. Elisabeth Carter, forensic linguist and criminologist at Kingston University London, said fraudsters create situations that appear entirely reasonable at the time.</p><p>“Fraudsters use recognised contexts, familiar social settings and embedded linguistic norms to make victims feel their decision-making is rational and reasonable in the moment,” Carter explained.</p><p>“What is actually happening is that they construct false realities in which those decisions end up causing financial and psychological harm.”</p><h2 id="financial-losses-continue-to-grow-as-reporting-remains-low">Financial losses continue to grow as reporting remains low</h2><p>The financial consequences extend beyond isolated incidents, particularly during a period when many households already face economic pressures.</p><p>Kaspersky found that victims in the UK lose an average of £458.45 per scam, while 9.1% reported losses exceeding £1,000, with more than a quarter (28%) saying they experienced three or more scam attempts within six months.</p><p>Researchers noted that millennials were especially vulnerable to investment-related fraud, with 40% reporting exposure to financial opportunity schemes.</p><p>The study also found over half (52%) of all scams occurred during the previous five months, suggesting the problem continues to accelerate rather than stabilize.</p><p>Marc Rivero, Lead Security Researcher at Kaspersky's Global Research and Analysis Team, warned that criminal groups are operating at an unprecedented scale.</p><p>“AI is accelerating the trend, helping scammers convincingly imitate brands, familiar voices, and personal relationships,” said Marc Rivero, Lead Security Researcher at Kaspersky's Global Research and Analysis Team.</p><p>“Simply being aware is no longer sufficient protection. People need to recognise risks earlier, before being pressured into hasty decisions."</p><p>Security specialists recommend combining caution with technical safeguards, including <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> capable of detecting malicious links in real time.</p><p>They also encourage stronger credential protection through a <a href="https://www.techradar.com/best/password-manager">password manager</a> and broader awareness of evolving scam tactics.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/simply-being-aware-is-no-longer-sufficient-protection-security-experts-warn-of-ai-boosted-scam-campaigns-that-can-trick-even-the-smartest-victims</link>
                                                                            <description>
                            <![CDATA[ AI-powered scams are tricking victims faster than ever, with many losing money within minutes through convincing fake identities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">obwCopPAjiwsGxFGYVXNPf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vaZaSfPx7aqf7NQMxSW9i9-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 21 Jun 2026 08:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vaZaSfPx7aqf7NQMxSW9i9-1280-80.png">
                                                            <media:credit><![CDATA[Kaspersky]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man looking at phone after being scammed by an AI tool]]></media:description>                                                            <media:text><![CDATA[Man looking at phone after being scammed by an AI tool]]></media:text>
                                <media:title type="plain"><![CDATA[Man looking at phone after being scammed by an AI tool]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vaZaSfPx7aqf7NQMxSW9i9-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nearly two-thirds of victims believe AI tools enabled their fraud experience</strong></li><li><strong>One in ten victims handed over money within just five minutes</strong></li><li><strong>Scammers moved across multiple platforms in 63% of incidents</strong></li></ul><p>Messaging scams are becoming increasingly sophisticated as criminals use AI to imitate trusted people, familiar brands, and everyday conversations.</p><p>New <a href="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2026/05/27050022/The_Great_Messaging_Heist_Report_2026_by_Kaspersky.pdf?kaspr=x75y" target="_blank" rel="nofollow">research</a> from Kaspersky suggests these schemes are succeeding with alarming speed, often convincing victims to hand over money within minutes.</p><p>The findings indicate that digital experience alone may no longer provide reliable protection against modern fraud attempts.</p><h2 id="ai-powered-scams-are-becoming-faster-and-more-convincing">AI-powered scams are becoming faster and more convincing</h2><p>The study found that nearly two-thirds of scam victims globally, or 64.5%, believed <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> played a role in the fraud attempts directed at them.</p><p>In the United Kingdom, 54% of respondents suspected criminals used deepfakes or synthetic voices to impersonate relatives, friends, or legitimate organizations, allowing scammers to create convincing scenarios that closely resemble genuine interactions and trusted relationships.</p><p>According to the research, more than half of UK victims completed payments or shared sensitive information within 30 minutes of initial contact.</p><p>More than 1 in 10 victims, representing 12.2%, did so within 5 minutes, demonstrating how rapidly these operations unfold.</p><p>Researchers also found nearly two-thirds (63%) of incidents moved across multiple communication platforms, helping fraudsters maintain credibility while avoiding suspicion.</p><p>The most common scams involved investment opportunities, affecting 40% of respondents, followed by fake delivery alert at 38% and brand impersonation schemes at 35%.</p><p>Dr. Elisabeth Carter, forensic linguist and criminologist at Kingston University London, said fraudsters create situations that appear entirely reasonable at the time.</p><p>“Fraudsters use recognised contexts, familiar social settings and embedded linguistic norms to make victims feel their decision-making is rational and reasonable in the moment,” Carter explained.</p><p>“What is actually happening is that they construct false realities in which those decisions end up causing financial and psychological harm.”</p><h2 id="financial-losses-continue-to-grow-as-reporting-remains-low">Financial losses continue to grow as reporting remains low</h2><p>The financial consequences extend beyond isolated incidents, particularly during a period when many households already face economic pressures.</p><p>Kaspersky found that victims in the UK lose an average of £458.45 per scam, while 9.1% reported losses exceeding £1,000, with more than a quarter (28%) saying they experienced three or more scam attempts within six months.</p><p>Researchers noted that millennials were especially vulnerable to investment-related fraud, with 40% reporting exposure to financial opportunity schemes.</p><p>The study also found over half (52%) of all scams occurred during the previous five months, suggesting the problem continues to accelerate rather than stabilize.</p><p>Marc Rivero, Lead Security Researcher at Kaspersky's Global Research and Analysis Team, warned that criminal groups are operating at an unprecedented scale.</p><p>“AI is accelerating the trend, helping scammers convincingly imitate brands, familiar voices, and personal relationships,” said Marc Rivero, Lead Security Researcher at Kaspersky's Global Research and Analysis Team.</p><p>“Simply being aware is no longer sufficient protection. People need to recognise risks earlier, before being pressured into hasty decisions."</p><p>Security specialists recommend combining caution with technical safeguards, including <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> capable of detecting malicious links in real time.</p><p>They also encourage stronger credential protection through a <a href="https://www.techradar.com/best/password-manager">password manager</a> and broader awareness of evolving scam tactics.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 100 days after the Iran war started — Tehran-backed group breaches California Water Service but claims they 'chose not to disrupt water access' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Iranian hackers accessed two Cal Water systems and leaked 5GB of data</strong></li><li><strong>A poorly secured GPS tool gave attackers a direct path inside Cal Water</strong></li><li><strong>Administrative credentials for seven California districts were published in plaintext online</strong></li></ul><p>Tehran-linked threat group Handala has claimed it successfully breached California Water Service and released a 5GB data dump as proof.</p><p>Cal Water is one of the largest investor-owned water utilities in the United States, serving millions of residential and commercial customers across California.</p><p>Handala described the breach as direct retaliation for recent US military actions in Iran, claiming it could disrupt water access but deliberately chose not to — for now.</p><h2 id="how-a-gps-tool-became-the-entry-point">How a GPS tool became the entry point</h2><p>Cybersecurity firm Dataminr analyzed the published data and identified two separate systems that Handala accessed during the breach.</p><p>The first was a customer billing database containing names, addresses, phone numbers, account numbers, and payment histories across multiple Cal Water districts.</p><p>The second was an internal RTKBase deployment — an open-source GPS base station platform used by field crews maintaining water infrastructure across California.</p><p>The RTKBase instance had been running continuously for approximately 783 hours at the time of access, with GPS correction data streaming across seven identified Cal Water districts.</p><p>Those districts included Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment spread across California.</p><p>The researchers believe that the GPS platform was not the end goal — it was the entry point into deeper infrastructure.</p><p>The RTKBase web interface was accessible via standard HTTP port 10000 across multiple district locations, making it straightforward for outside actors to locate and access.</p><p>It was deployed on lightweight hardware that offered minimal resistance against unauthorized entry from the internet.</p><p>Administrative credentials for the platform appeared in the published dump in plaintext, giving anyone who downloaded it immediate access to the entire system.</p><p>Full network infrastructure details for all seven districts were equally exposed, leaving Cal Water's security team with virtually nothing intact to protect.</p><h2 id="a-pattern-that-should-concern-every-water-utility">A pattern that should concern every water utility</h2><p>Handala's history makes the "chose not to disrupt" framing worth treating with considerable skepticism from any serious security perspective.</p><p>The group deployed a destructive wiper against Stryker in March 2026 that disrupted manufacturing and shipping — following the same data-theft-first pattern documented in this breach.</p><p>"Handala's operational pattern frequently involves an initial claim followed by escalated action," Dataminr's report concluded.</p><p>"Security teams should treat the current disclosure as a possible precursor to a destructive follow-on and posture accordingly."</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory this year warning of Iranian groups targeting US water sector technologies.</p><p>This breach is an indication that Iranian cyber threats to US water infrastructure are no longer theoretical.</p><p>Cal Water has not publicly acknowledged the breach, but affected customers now face elevated phishing risks given that their names, addresses, phone numbers, and account details are publicly available. </p><p>Via <a href="https://securityaffairs.com/193565/uncategorized/iran-linked-handala-breached-a-california-water-utility-it-could-have-done-worse-and-it-knows-that.html" target="_blank" rel="nofollow">Security Affairs</a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/100-days-after-the-iran-war-started-tehran-backed-group-just-breached-california-water-service-but-claims-they-chose-not-to-disrupt-water-access</link>
                                                                            <description>
                            <![CDATA[ Iranian-linked group Handala breached California Water Service, leaking 5GB of customer data and exposing critical GPS infrastructure across seven districts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GEad45HVtqTWmprj8U73pV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jun 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png">
                                                            <media:credit><![CDATA[Veolia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:description>                                                            <media:text><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:text>
                                <media:title type="plain"><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Iranian hackers accessed two Cal Water systems and leaked 5GB of data</strong></li><li><strong>A poorly secured GPS tool gave attackers a direct path inside Cal Water</strong></li><li><strong>Administrative credentials for seven California districts were published in plaintext online</strong></li></ul><p>Tehran-linked threat group Handala has claimed it successfully breached California Water Service and released a 5GB data dump as proof.</p><p>Cal Water is one of the largest investor-owned water utilities in the United States, serving millions of residential and commercial customers across California.</p><p>Handala described the breach as direct retaliation for recent US military actions in Iran, claiming it could disrupt water access but deliberately chose not to — for now.</p><h2 id="how-a-gps-tool-became-the-entry-point">How a GPS tool became the entry point</h2><p>Cybersecurity firm Dataminr analyzed the published data and identified two separate systems that Handala accessed during the breach.</p><p>The first was a customer billing database containing names, addresses, phone numbers, account numbers, and payment histories across multiple Cal Water districts.</p><p>The second was an internal RTKBase deployment — an open-source GPS base station platform used by field crews maintaining water infrastructure across California.</p><p>The RTKBase instance had been running continuously for approximately 783 hours at the time of access, with GPS correction data streaming across seven identified Cal Water districts.</p><p>Those districts included Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment spread across California.</p><p>The researchers believe that the GPS platform was not the end goal — it was the entry point into deeper infrastructure.</p><p>The RTKBase web interface was accessible via standard HTTP port 10000 across multiple district locations, making it straightforward for outside actors to locate and access.</p><p>It was deployed on lightweight hardware that offered minimal resistance against unauthorized entry from the internet.</p><p>Administrative credentials for the platform appeared in the published dump in plaintext, giving anyone who downloaded it immediate access to the entire system.</p><p>Full network infrastructure details for all seven districts were equally exposed, leaving Cal Water's security team with virtually nothing intact to protect.</p><h2 id="a-pattern-that-should-concern-every-water-utility">A pattern that should concern every water utility</h2><p>Handala's history makes the "chose not to disrupt" framing worth treating with considerable skepticism from any serious security perspective.</p><p>The group deployed a destructive wiper against Stryker in March 2026 that disrupted manufacturing and shipping — following the same data-theft-first pattern documented in this breach.</p><p>"Handala's operational pattern frequently involves an initial claim followed by escalated action," Dataminr's report concluded.</p><p>"Security teams should treat the current disclosure as a possible precursor to a destructive follow-on and posture accordingly."</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory this year warning of Iranian groups targeting US water sector technologies.</p><p>This breach is an indication that Iranian cyber threats to US water infrastructure are no longer theoretical.</p><p>Cal Water has not publicly acknowledged the breach, but affected customers now face elevated phishing risks given that their names, addresses, phone numbers, and account details are publicly available. </p><p>Via <a href="https://securityaffairs.com/193565/uncategorized/iran-linked-handala-breached-a-california-water-utility-it-could-have-done-worse-and-it-knows-that.html" target="_blank" rel="nofollow">Security Affairs</a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kali365 is a sophisticated phishing-as-a-service platform, also known as Octopi365 and Freedom365, that targets Microsoft accounts</strong></li><li><strong>It was first detected by security firm Huntress in May 2026 when examining a slew of Microsoft 365 logins originating from China</strong></li><li><strong>The FBI issues a warning detailing the process as part of a public service announcement</strong></li></ul><p>Phishing attacks are hardly new, with an estimated 3.4 billion malicious emails sent daily, accounting for a mammoth 1.2% of all email traffic.</p><p>Google alone blocks approximately 100 million phishing emails daily, as threat actors continue to evolve their approaches, using unique campaigns, AI-generated content, and, lately, QR codes to lure unsuspecting victims.</p><p>A recent phishing-as-a-service toolkit <a href="https://www.huntress.com/blog/kali365-device-code-phishing-kit" target="_blank">detected by cybersecurity company Huntress</a>, however, stands out for its sophistication, scale, and success rate.</p><h2 id="a-sophisticated-phishing-service-for-hire">A sophisticated phishing service for hire</h2><p>What makes Kali365 unique versus its peers is the scale at which it operates and the methods it uses. Unlike most phishing operations, it is a tool with at least 33 built-in templates that impersonate Microsoft products and services, 100 API endpoints, and role-based access control for phishing teams.</p><p>In addition to being an AI-enabled phishing, it also has a sophisticated payout pipeline, a crypto payment gateway integration, tiered access to the software suite, and, for those looking for a complete offering, a desktop application for operators.</p><p>Kali365 and its variants and clones, such as Octopi365 and Freedom365, do not, however, directly compromise or bypass MFA; instead, they use a set of highly legitimate emails and calls to action that then steal session cookies and OAuth tokens, allowing access to a victim's account.</p><p>The process itself is seamless; a potential victim sees a Microsoft website, an SSL certificate, and no warnings that they are effectively handing over access to a bad actor, who then uses their authenticated token to access their account. The AI-generated lures themselves are sophisticated, but as the <a href="https://www.ic3.gov/PSA/2026/PSA260521" target="_blank">FBI points out</a>, they still require a user to be phished via email, with many impersonating "trusted cloud productivity and document-sharing services."</p><p>The more damning use of AI, however, is where Anthropic's Claude AI model is used to read intercepted email threads, score them for fraud potential, and draft convincing reply messages, complete with fabricated banking details and a manufactured sense of urgency, to be sent from the victim's own mailbox. </p><p>While the FBI's warning stands, it also somewhat acknowledges that this is not an easy phishing attempt to avoid, given the scale, the multitude of phishing attack vectors, and the "legitimate" look it has compared to most of its competition. Resolving this would require a change on Microsoft's end to close security loopholes that enable such authentication transfers, but for now, any affected individuals can only <a href="https://www.ic3.gov/" target="_blank">report their experiences here</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication</link>
                                                                            <description>
                            <![CDATA[ Kali365 abuses the current OAuth device code flow on Microsoft accounts in a sophisticated attempt to dupe users into signing into their accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3TQ2FNepmP2KaHKXkWEM34</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:description>                                                            <media:text><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kali365 is a sophisticated phishing-as-a-service platform, also known as Octopi365 and Freedom365, that targets Microsoft accounts</strong></li><li><strong>It was first detected by security firm Huntress in May 2026 when examining a slew of Microsoft 365 logins originating from China</strong></li><li><strong>The FBI issues a warning detailing the process as part of a public service announcement</strong></li></ul><p>Phishing attacks are hardly new, with an estimated 3.4 billion malicious emails sent daily, accounting for a mammoth 1.2% of all email traffic.</p><p>Google alone blocks approximately 100 million phishing emails daily, as threat actors continue to evolve their approaches, using unique campaigns, AI-generated content, and, lately, QR codes to lure unsuspecting victims.</p><p>A recent phishing-as-a-service toolkit <a href="https://www.huntress.com/blog/kali365-device-code-phishing-kit" target="_blank">detected by cybersecurity company Huntress</a>, however, stands out for its sophistication, scale, and success rate.</p><h2 id="a-sophisticated-phishing-service-for-hire">A sophisticated phishing service for hire</h2><p>What makes Kali365 unique versus its peers is the scale at which it operates and the methods it uses. Unlike most phishing operations, it is a tool with at least 33 built-in templates that impersonate Microsoft products and services, 100 API endpoints, and role-based access control for phishing teams.</p><p>In addition to being an AI-enabled phishing, it also has a sophisticated payout pipeline, a crypto payment gateway integration, tiered access to the software suite, and, for those looking for a complete offering, a desktop application for operators.</p><p>Kali365 and its variants and clones, such as Octopi365 and Freedom365, do not, however, directly compromise or bypass MFA; instead, they use a set of highly legitimate emails and calls to action that then steal session cookies and OAuth tokens, allowing access to a victim's account.</p><p>The process itself is seamless; a potential victim sees a Microsoft website, an SSL certificate, and no warnings that they are effectively handing over access to a bad actor, who then uses their authenticated token to access their account. The AI-generated lures themselves are sophisticated, but as the <a href="https://www.ic3.gov/PSA/2026/PSA260521" target="_blank">FBI points out</a>, they still require a user to be phished via email, with many impersonating "trusted cloud productivity and document-sharing services."</p><p>The more damning use of AI, however, is where Anthropic's Claude AI model is used to read intercepted email threads, score them for fraud potential, and draft convincing reply messages, complete with fabricated banking details and a manufactured sense of urgency, to be sent from the victim's own mailbox. </p><p>While the FBI's warning stands, it also somewhat acknowledges that this is not an easy phishing attempt to avoid, given the scale, the multitude of phishing attack vectors, and the "legitimate" look it has compared to most of its competition. Resolving this would require a change on Microsoft's end to close security loopholes that enable such authentication transfers, but for now, any affected individuals can only <a href="https://www.ic3.gov/" target="_blank">report their experiences here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'These attacks don't look like break-ins' — HP warns hackers are turning popular remote access tools into dangerous, stealthy backdoors ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Legitimate software is now the most dangerous weapon in a hacker's arsenal, HP warns</strong></li><li><strong>Tax deadline phishing emails are opening doors that security scanners never flag</strong></li><li><strong>Fake dating app downloads are delivering full remote access to attackers instantly</strong></li></ul><p>Cybercriminals are exploiting legitimate remote access applications such as LogMeIn and ScreenConnect to take control of victim devices without triggering standard security alerts, experts have warned.</p><p>HP's latest <a href="https://www.hp.com/us-en/newsroom/press-releases/2026/HP-attackers-are-turning-legitimate-remote-access-tools-into-backdoors.html" target="_blank" rel="nofollow">Threat Insights Report</a>, covering January through March 2026, documents how attackers are deliberately blending malicious activity into normal IT behavior to avoid detection.</p><p>The report draws on data from millions of endpoints running HP Wolf Security across the period under review, and found the campaigns follow a consistent pattern built around social engineering rather than technical exploits.</p><h2 id="how-trust-becomes-the-weapon">How trust becomes the weapon</h2><p>Legitimate software becomes the perfect disguise precisely because security tools are least likely to flag applications they already recognize and trust.</p><p>When an attacker controls a familiar remote access tool on a victim's device, nothing in the security stack raises an alarm.</p><p>That invisibility starts at the very first step — attackers used tax year-end phishing <a href="https://www.techradar.com/news/best-email-provider">emails</a> and fake desktop application downloads, including fraudulent dating website installers, to persuade users into installing remote access tools that they control.</p><p>Once installed, those tools gave attackers total device control while appearing indistinguishable from routine IT activity.</p><p>"What stands out in these campaigns is how easily legitimate remote access tools are being turned into entry points for attackers," said Patrick Schläpfer, Principal Threat Researcher at HP Security Lab.</p><p>"By combining trusted software with carefully designed social engineering — tied to events like the end of the tax year — it's getting even harder to distinguish what can and can't be trusted."</p><p>Separate campaigns uncovered in the same period used fake cryptocurrency wallet recovery tools distributed through code-sharing platforms and media download sites.</p><p>Those tools, rather than helping users recover lost wallets, harvested credentials, wallet data, and system information before packaging everything into archive files for exfiltration.</p><p>The emoji-heavy scripts used in these attacks showed characteristics consistent with AI-assisted coding.</p><p>This suggests that <a href="https://www.techradar.com/pro/best-vibe-coding-tools">vibe coding tools</a> are now lowering the barrier for building functional malware.</p><h2 id="malware-hides-in-plain-sight">Malware hides in plain sight</h2><p>HP's report also documented ClickFix campaigns disguising <a href="https://www.techradar.com/best/best-malware-removal">malware</a> as audio files through convincing fake websites and realistic CAPTCHA prompts.</p><p>Victims unknowingly execute the malicious code in the background while believing they were completing routine security checks.</p><p>At least 11% of email threats identified by HP Wolf Security during the period bypassed one or more email gateway scanners entirely.</p><p>Executable files accounted for the largest share of malware delivery at 39%, followed by archive files at 38% and PDF documents at 10%.</p><p>"These attacks don't look like break-ins — they look like business as usual, blending in with normal IT activity and avoiding the warning signs associated with malware," said Alex Holland, Principal Threat Researcher at HP Security Lab</p><p>Holland added that organizations should restrict unnecessary privileges, control software installation, and isolate risky activity such as downloads and unknown links.</p><p>Enterprise security teams are advised to adjust their defenses to account for attacks that look legitimate, rather than suspicious. </p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/these-attacks-dont-look-like-break-ins-hp-warns-hackers-are-turning-popular-remote-access-tools-into-dangerous-stealthy-backdoors</link>
                                                                            <description>
                            <![CDATA[ HP's latest threat report reveals hackers are abusing legitimate remote access tools and fake downloads to silently compromise corporate devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p59kSjYoTKzZrhc4SYFBwm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/abAdPvAymwxfL59qPnT4in-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 20:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/abAdPvAymwxfL59qPnT4in-1280-80.jpg">
                                                            <media:credit><![CDATA[ozrimoz / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/abAdPvAymwxfL59qPnT4in-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Legitimate software is now the most dangerous weapon in a hacker's arsenal, HP warns</strong></li><li><strong>Tax deadline phishing emails are opening doors that security scanners never flag</strong></li><li><strong>Fake dating app downloads are delivering full remote access to attackers instantly</strong></li></ul><p>Cybercriminals are exploiting legitimate remote access applications such as LogMeIn and ScreenConnect to take control of victim devices without triggering standard security alerts, experts have warned.</p><p>HP's latest <a href="https://www.hp.com/us-en/newsroom/press-releases/2026/HP-attackers-are-turning-legitimate-remote-access-tools-into-backdoors.html" target="_blank" rel="nofollow">Threat Insights Report</a>, covering January through March 2026, documents how attackers are deliberately blending malicious activity into normal IT behavior to avoid detection.</p><p>The report draws on data from millions of endpoints running HP Wolf Security across the period under review, and found the campaigns follow a consistent pattern built around social engineering rather than technical exploits.</p><h2 id="how-trust-becomes-the-weapon">How trust becomes the weapon</h2><p>Legitimate software becomes the perfect disguise precisely because security tools are least likely to flag applications they already recognize and trust.</p><p>When an attacker controls a familiar remote access tool on a victim's device, nothing in the security stack raises an alarm.</p><p>That invisibility starts at the very first step — attackers used tax year-end phishing <a href="https://www.techradar.com/news/best-email-provider">emails</a> and fake desktop application downloads, including fraudulent dating website installers, to persuade users into installing remote access tools that they control.</p><p>Once installed, those tools gave attackers total device control while appearing indistinguishable from routine IT activity.</p><p>"What stands out in these campaigns is how easily legitimate remote access tools are being turned into entry points for attackers," said Patrick Schläpfer, Principal Threat Researcher at HP Security Lab.</p><p>"By combining trusted software with carefully designed social engineering — tied to events like the end of the tax year — it's getting even harder to distinguish what can and can't be trusted."</p><p>Separate campaigns uncovered in the same period used fake cryptocurrency wallet recovery tools distributed through code-sharing platforms and media download sites.</p><p>Those tools, rather than helping users recover lost wallets, harvested credentials, wallet data, and system information before packaging everything into archive files for exfiltration.</p><p>The emoji-heavy scripts used in these attacks showed characteristics consistent with AI-assisted coding.</p><p>This suggests that <a href="https://www.techradar.com/pro/best-vibe-coding-tools">vibe coding tools</a> are now lowering the barrier for building functional malware.</p><h2 id="malware-hides-in-plain-sight">Malware hides in plain sight</h2><p>HP's report also documented ClickFix campaigns disguising <a href="https://www.techradar.com/best/best-malware-removal">malware</a> as audio files through convincing fake websites and realistic CAPTCHA prompts.</p><p>Victims unknowingly execute the malicious code in the background while believing they were completing routine security checks.</p><p>At least 11% of email threats identified by HP Wolf Security during the period bypassed one or more email gateway scanners entirely.</p><p>Executable files accounted for the largest share of malware delivery at 39%, followed by archive files at 38% and PDF documents at 10%.</p><p>"These attacks don't look like break-ins — they look like business as usual, blending in with normal IT activity and avoiding the warning signs associated with malware," said Alex Holland, Principal Threat Researcher at HP Security Lab</p><p>Holland added that organizations should restrict unnecessary privileges, control software installation, and isolate risky activity such as downloads and unknown links.</p><p>Enterprise security teams are advised to adjust their defenses to account for attacks that look legitimate, rather than suspicious. </p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI gives first peek inside 22,000-square-foot town it’s built for digital crime training — the ‘one of a kind’ facility has a gas station, houses, and a data center with 200 hackable servers ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The FBI has built an entire town to help train its agents</strong></li><li><strong>The town contains houses, businesses, and 200 hackable servers</strong></li><li><strong>The idea is to give agents hands-on experience so they’re ready for the field</strong></li></ul><p>In the never-ending cat-and-mouse game between hackers and law enforcement, it helps the latter to know exactly what they’re up against. Usually, that might mean sitting in a classroom and getting a little hands-on time with a hacked server or laptop. But that’s not the case with the FBI’s Kinetic Cyber Range — no, this time the US’s Federal Bureau of Investigation went out and built a whole town to keep itself sharp. </p><p>The 22,000-square-foot <a href="https://www.fbi.gov/news/stories/inside-the-fbis-kinetic-cyber-range" target="_blank">Kinetic Cyber Range</a> is built to be as lifelike as possible. Pay it a visit, and you’ll find 11 different facilities, including houses, a data center, a gaming arcade, a convenience store, a hotel, and much more. It’s designed to replicate the kind of town you might find anywhere in America, yet it’s all contained within an enormous hangar at the FBI’s training campus in Huntsville, Alabama. </p><p>All the businesses and tech in the ersatz community can be <a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know" target="_blank">hacked</a>, allowing students to put their skills to the test. Would-be cyber officers will encounter <a href="https://www.techradar.com/best/firewall">firewalls</a>, email systems, file directories, and more, helping to prepare them for future digital investigations. That said, the Kinetic Cyber Range is designed to ensure that nothing nefarious spills out of its secure bounds and into the wider world. </p><p>In addition to the FBI, the facility can be used by NASA, the US Army, and local law enforcement agencies. The idea is to get people up to speed with the latest cyber techs — including drone software, vehicle forensics, and the internet of things.</p><h2 id="facing-emerging-threats">Facing emerging threats</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1400px;"><p class="vanilla-image-block" style="padding-top:56.29%;"><img id="cAPxpbP4WXZ4rJur8xF6AZ" name="FBI Kinetic Cyber Range 2" alt="A person working inside the FBI's Kinetic Cyber Range training facility." src="https://cdn.mos.cms.futurecdn.net/cAPxpbP4WXZ4rJur8xF6AZ.jpg" mos="" align="middle" fullscreen="" width="1400" height="788" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: FBI)</span></figcaption></figure><p>Given how <a href="https://www.techradar.com/pro/security/fraud-wont-be-tolerated-in-this-country-any-longer-fbi-releases-most-wanted-fraudsters-list-to-help-fight-the-crime-that-costs-americans-tens-of-billions-of-dollars-every-year">incredibly lucrative</a> the cybercrime industry is for <a href="https://www.techradar.com/pro/security/scams-are-getting-so-much-more-efficient-new-study-warns-over-half-of-americans-hit-by-fraud-in-2025-and-the-figure-is-only-going-to-get-worse">hackers and fraudsters</a>, it makes sense for law enforcement to seek as much real-world, hands-on time as possible. Theory alone will only provide so much education, and without encountering the kinds of situations you might find in the real world, FBI agents will be a step behind their adversaries. </p><p>Speaking on the <a href="https://www.youtube.com/watch?v=a8UMAc_8L5c" target="_blank">FBI’s YouTube channel</a>, David Beachboard, Program Manager of the Kinetic Cyber Range, described the training location as “one of a kind” and said that “there is no facility like this in the world … This is about as real as it’s going to get before people go out in the field.” </p><p>Interestingly, students at the center will also be involved in various roleplay exercises that mimic those they’ll encounter outside the facility, from conducting interviews with business executives whose premises are being searched to dealing with medical staff who are concerned for patient welfare in the middle of a <a href="https://www.techradar.com/pro/most-ransomware-attacks-are-opportunistic-heres-how-you-can-stop-attackers">ransomware</a> attack. It’s these scenarios that are difficult or impossible to fully replicate inside a classroom. </p><p>According to the FBI, more than 1,400 students have passed through the Kinetic Cyber Range since its opening in February 2025, with the training being regularly updated to cover <a href="https://www.techradar.com/pro/how-emerging-tech-is-rewriting-cyberwarfare">emerging threats</a>. As threat actors evolve, so too must those attempting to stop them. No doubt Beachboard and the FBI hope the Kinetic Cyber Range will play a key role in doing just that.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/cyber-security/fbi-gives-first-peek-inside-22-000-square-foot-town-its-built-for-digital-crime-training-the-one-of-a-kind-facility-has-a-gas-station-houses-and-a-data-center-with-200-hackable-servers</link>
                                                                            <description>
                            <![CDATA[ The FBI has built a town with homes, businesses and hackable servers to help train its cyber agents. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bNAts2q82S3t2mKTdnxjmB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gfW7CHQv24GE99jKuh54CZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 03:46:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gfW7CHQv24GE99jKuh54CZ-1280-80.jpg">
                                                            <media:credit><![CDATA[FBI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Buildings inside the FBI&#039;s Kinetic Cyber Range training facility.]]></media:description>                                                            <media:text><![CDATA[Buildings inside the FBI&#039;s Kinetic Cyber Range training facility.]]></media:text>
                                <media:title type="plain"><![CDATA[Buildings inside the FBI&#039;s Kinetic Cyber Range training facility.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gfW7CHQv24GE99jKuh54CZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The FBI has built an entire town to help train its agents</strong></li><li><strong>The town contains houses, businesses, and 200 hackable servers</strong></li><li><strong>The idea is to give agents hands-on experience so they’re ready for the field</strong></li></ul><p>In the never-ending cat-and-mouse game between hackers and law enforcement, it helps the latter to know exactly what they’re up against. Usually, that might mean sitting in a classroom and getting a little hands-on time with a hacked server or laptop. But that’s not the case with the FBI’s Kinetic Cyber Range — no, this time the US’s Federal Bureau of Investigation went out and built a whole town to keep itself sharp. </p><p>The 22,000-square-foot <a href="https://www.fbi.gov/news/stories/inside-the-fbis-kinetic-cyber-range" target="_blank">Kinetic Cyber Range</a> is built to be as lifelike as possible. Pay it a visit, and you’ll find 11 different facilities, including houses, a data center, a gaming arcade, a convenience store, a hotel, and much more. It’s designed to replicate the kind of town you might find anywhere in America, yet it’s all contained within an enormous hangar at the FBI’s training campus in Huntsville, Alabama. </p><p>All the businesses and tech in the ersatz community can be <a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know" target="_blank">hacked</a>, allowing students to put their skills to the test. Would-be cyber officers will encounter <a href="https://www.techradar.com/best/firewall">firewalls</a>, email systems, file directories, and more, helping to prepare them for future digital investigations. That said, the Kinetic Cyber Range is designed to ensure that nothing nefarious spills out of its secure bounds and into the wider world. </p><p>In addition to the FBI, the facility can be used by NASA, the US Army, and local law enforcement agencies. The idea is to get people up to speed with the latest cyber techs — including drone software, vehicle forensics, and the internet of things.</p><h2 id="facing-emerging-threats">Facing emerging threats</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1400px;"><p class="vanilla-image-block" style="padding-top:56.29%;"><img id="cAPxpbP4WXZ4rJur8xF6AZ" name="FBI Kinetic Cyber Range 2" alt="A person working inside the FBI's Kinetic Cyber Range training facility." src="https://cdn.mos.cms.futurecdn.net/cAPxpbP4WXZ4rJur8xF6AZ.jpg" mos="" align="middle" fullscreen="" width="1400" height="788" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: FBI)</span></figcaption></figure><p>Given how <a href="https://www.techradar.com/pro/security/fraud-wont-be-tolerated-in-this-country-any-longer-fbi-releases-most-wanted-fraudsters-list-to-help-fight-the-crime-that-costs-americans-tens-of-billions-of-dollars-every-year">incredibly lucrative</a> the cybercrime industry is for <a href="https://www.techradar.com/pro/security/scams-are-getting-so-much-more-efficient-new-study-warns-over-half-of-americans-hit-by-fraud-in-2025-and-the-figure-is-only-going-to-get-worse">hackers and fraudsters</a>, it makes sense for law enforcement to seek as much real-world, hands-on time as possible. Theory alone will only provide so much education, and without encountering the kinds of situations you might find in the real world, FBI agents will be a step behind their adversaries. </p><p>Speaking on the <a href="https://www.youtube.com/watch?v=a8UMAc_8L5c" target="_blank">FBI’s YouTube channel</a>, David Beachboard, Program Manager of the Kinetic Cyber Range, described the training location as “one of a kind” and said that “there is no facility like this in the world … This is about as real as it’s going to get before people go out in the field.” </p><p>Interestingly, students at the center will also be involved in various roleplay exercises that mimic those they’ll encounter outside the facility, from conducting interviews with business executives whose premises are being searched to dealing with medical staff who are concerned for patient welfare in the middle of a <a href="https://www.techradar.com/pro/most-ransomware-attacks-are-opportunistic-heres-how-you-can-stop-attackers">ransomware</a> attack. It’s these scenarios that are difficult or impossible to fully replicate inside a classroom. </p><p>According to the FBI, more than 1,400 students have passed through the Kinetic Cyber Range since its opening in February 2025, with the training being regularly updated to cover <a href="https://www.techradar.com/pro/how-emerging-tech-is-rewriting-cyberwarfare">emerging threats</a>. As threat actors evolve, so too must those attempting to stop them. No doubt Beachboard and the FBI hope the Kinetic Cyber Range will play a key role in doing just that.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How scammers use "scraped New York Times content" to trick security scanners — and exploit "free" Google Cloud links to flood your inbox ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>More than 12,000 servers supported a coordinated phishing infrastructure worldwide</strong></li><li><strong>Google Cloud links helped phishing emails appear safer than reality</strong></li><li><strong>Fake New York Times pages acted as decoys for scanners</strong></li></ul><p>When a suspicious email lands in your inbox promising financial rewards or urgent payment requests, the infrastructure behind that email is rarely what it appears to be.</p><p>An investigation by <a href="https://www.comparitech.com/news/how-spammers-are-hiding-behind-google-and-the-new-york-times/" target="_blank" rel="nofollow">Comparitech</a> revealed a coordinated spam and phishing network spanning 12,704 servers in 55 countries.</p><p>These phishing emails are tied to fake financial rewards and similar scams, using tactics designed to evade security tools such as antivirus and <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware protection</a> systems that many users depend on.</p><h2 id="trusted-google-links-help-the-campaign-evade-detection">Trusted Google links help the campaign evade detection</h2><p>The campaign begins with unsolicited emails promoting financial rewards, health products, gambling offers, or urgent payment requests through embedded links.</p><p>Rather than directing recipients immediately to attacker-controlled websites, the links first route through Google Cloud Storage pages hosted on Google's infrastructure.</p><p>That approach matters because familiar Google domains<a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know"> generally attract less scrutiny</a> from users and automated filtering systems than unknown websites.</p><p>Google-owned URLs passed easily through email gateways, <a href="https://www.techradar.com/best/firewall">firewalls</a>, and reputation filters that routinely extend trust to Google domains without deeper inspection.</p><p>Researchers found that attackers uploaded simple HTML and JavaScript files to cloud storage locations, allowing them to redirect visitors elsewhere without placing obviously malicious content on Google's servers.</p><p>This separation between the initial link and the final destination also provides operational flexibility for campaign operators.</p><p>Redirect destinations can be changed at any time without requiring modifications to emails that have already been distributed to potential victims.</p><p>During testing, researchers repeatedly encountered nearly identical landing pages displaying news content copied from <em>The New York Times</em>.</p><p>These pages appeared designed to serve as harmless decoys for security products, researchers, and visitors who did not meet specific selection criteria.</p><p>The infrastructure supporting these pages shared common software configurations, matching asset directories, similar redirect behaviour, and largely outdated server environments.</p><h2 id="the-scale-is-difficult-to-dismiss">The scale is difficult to dismiss</h2><p>The research identified the network through a single CSS file path — assets/ayt/css/main.css — repeated identically across thousands of servers.</p><p>This pattern points to a centralized deployment rather than independent operators - of the 12,704 servers identified, 99.8% ran end-of-life software with no active security updates, spread across 412 hosting providers in dozens of jurisdictions.</p><p>That geographic spread was almost certainly deliberate — takedowns targeting one provider leave the rest of the network entirely intact.</p><p>Checking 5,000 of those servers against a crowd-sourced IP reputation database revealed that 89% carried no prior abuse history.</p><p>This suggests that the infrastructure was either recently provisioned or rotated frequently enough to stay ahead of <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> and threat intelligence systems.</p><p>Anyone who entered personal information on any page reached through one of these emails should treat that data as compromised.</p><p>Such users have to change their passwords immediately, especially where the password is reused across multiple services.</p><p>Furthermore, it is important to constantly monitor all financial accounts for unusual activities no matter how small they may appear initially.</p><p>Clicking a link without entering any information still carried a consequence. That click confirmed to the operators that the email address was live and active.</p><p>This means the email is likely to receive increased volumes of spam in the future, raising the risk of exposure to additional phishing attempts and fraudulent schemes.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/how-scammers-use-scraped-new-york-times-content-to-trick-security-scanners-and-exploit-free-google-cloud-links-to-flood-your-inbox</link>
                                                                            <description>
                            <![CDATA[ Researchers uncovered a global phishing network using Google Cloud redirects and copied news content across thousands of coordinated servers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QHPZ4FoC5h5Sim29zhDFKb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 23:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>More than 12,000 servers supported a coordinated phishing infrastructure worldwide</strong></li><li><strong>Google Cloud links helped phishing emails appear safer than reality</strong></li><li><strong>Fake New York Times pages acted as decoys for scanners</strong></li></ul><p>When a suspicious email lands in your inbox promising financial rewards or urgent payment requests, the infrastructure behind that email is rarely what it appears to be.</p><p>An investigation by <a href="https://www.comparitech.com/news/how-spammers-are-hiding-behind-google-and-the-new-york-times/" target="_blank" rel="nofollow">Comparitech</a> revealed a coordinated spam and phishing network spanning 12,704 servers in 55 countries.</p><p>These phishing emails are tied to fake financial rewards and similar scams, using tactics designed to evade security tools such as antivirus and <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware protection</a> systems that many users depend on.</p><h2 id="trusted-google-links-help-the-campaign-evade-detection">Trusted Google links help the campaign evade detection</h2><p>The campaign begins with unsolicited emails promoting financial rewards, health products, gambling offers, or urgent payment requests through embedded links.</p><p>Rather than directing recipients immediately to attacker-controlled websites, the links first route through Google Cloud Storage pages hosted on Google's infrastructure.</p><p>That approach matters because familiar Google domains<a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know"> generally attract less scrutiny</a> from users and automated filtering systems than unknown websites.</p><p>Google-owned URLs passed easily through email gateways, <a href="https://www.techradar.com/best/firewall">firewalls</a>, and reputation filters that routinely extend trust to Google domains without deeper inspection.</p><p>Researchers found that attackers uploaded simple HTML and JavaScript files to cloud storage locations, allowing them to redirect visitors elsewhere without placing obviously malicious content on Google's servers.</p><p>This separation between the initial link and the final destination also provides operational flexibility for campaign operators.</p><p>Redirect destinations can be changed at any time without requiring modifications to emails that have already been distributed to potential victims.</p><p>During testing, researchers repeatedly encountered nearly identical landing pages displaying news content copied from <em>The New York Times</em>.</p><p>These pages appeared designed to serve as harmless decoys for security products, researchers, and visitors who did not meet specific selection criteria.</p><p>The infrastructure supporting these pages shared common software configurations, matching asset directories, similar redirect behaviour, and largely outdated server environments.</p><h2 id="the-scale-is-difficult-to-dismiss">The scale is difficult to dismiss</h2><p>The research identified the network through a single CSS file path — assets/ayt/css/main.css — repeated identically across thousands of servers.</p><p>This pattern points to a centralized deployment rather than independent operators - of the 12,704 servers identified, 99.8% ran end-of-life software with no active security updates, spread across 412 hosting providers in dozens of jurisdictions.</p><p>That geographic spread was almost certainly deliberate — takedowns targeting one provider leave the rest of the network entirely intact.</p><p>Checking 5,000 of those servers against a crowd-sourced IP reputation database revealed that 89% carried no prior abuse history.</p><p>This suggests that the infrastructure was either recently provisioned or rotated frequently enough to stay ahead of <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> and threat intelligence systems.</p><p>Anyone who entered personal information on any page reached through one of these emails should treat that data as compromised.</p><p>Such users have to change their passwords immediately, especially where the password is reused across multiple services.</p><p>Furthermore, it is important to constantly monitor all financial accounts for unusual activities no matter how small they may appear initially.</p><p>Clicking a link without entering any information still carried a consequence. That click confirmed to the operators that the email address was live and active.</p><p>This means the email is likely to receive increased volumes of spam in the future, raising the risk of exposure to additional phishing attempts and fraudulent schemes.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean hackers are at it again — phishing scheme targets hundreds of workers to try and steal crypto and more ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UNK_DeadDrop targets developers with email‑based fake job lures</strong></li><li><strong>Campaign mirrors Lazarus tactics but uses new self‑contained payloads</strong></li><li><strong>Proofpoint says shift to mass phishing shows industrialized NK ops</strong></li></ul><p>Lazarus is not the only North Korean threat actor that is luring software developers with fake jobs - there is also a hacking group called UNK_DeadDrop now doing a similar thing, but with notable differences.</p><p>Security researchers at Proofpoint published an in-depth <a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal" target="_blank">report</a> looking into an ongoing campaign not unlike the Contagious Interview one.</p><p>For those unaware of Contagious Interview, it is one of two major Lazarus campaigns, the second one being Operation DreamJob. The crooks would fake everything - a company, its employees, as well as projects, and then go to LinkedIn for a “hiring spree.” They would reach out to software developers working in high-profile AI and Web 3 organizations and would offer high-paying jobs and a chance to work on exciting new projects.</p><h2 id="similarities-and-differences">Similarities and differences</h2><p>The hiring process, however, would include a trial assignment, which often required the victims to run <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malicious code</a> from GitHub. After infecting their targets with infostealers, the crooks would access company profiles, exfiltrate crypto wallet information, and then steal as many tokens as possible. </p><p>According to some sources, <a href="https://www.techradar.com/pro/lazarus-and-kimsuky-prove-why-infrastructure-level-analysis-is-crucial-for-cybersecurity" target="_blank">Lazarus</a> alone was able to steal billions of dollars in crypto throughout the years.</p><p>While UNK_DeadDrop is more-or-less doing the same thing, its approach is somewhat different. Instead of using LinkedIn for initial contact, these attackers rely mostly on email. They don’t arrange fake interviews, but rather just send unsolicited job offers or code review requests. And finally, they use a new, self-contained payload distinct from what was previously seen in Contagious Interview campaigns. </p><p>“UNK_DeadDrop activity suggests North Korea-aligned operations targeting developers for financial gain are maturing and evolving,” Proofpoint’s researchers concluded. </p><p>“The shift from active social engineering over social media platforms to conduct fake interviews to large campaigns of recruitment-themed phishing emails distributing links to malicious repositories could indicate an actor industrializing and scaling operations.”</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/north-korean-hackers-are-at-it-again-phishing-scheme-targets-hundreds-of-workers-to-try-and-steal-crypto-and-more</link>
                                                                            <description>
                            <![CDATA[ Lazarus is getting company as UNK_DeadDrop starts luring devs with fake jobs, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ujahv2UUX5DRFMXvby7JzP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jun 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UNK_DeadDrop targets developers with email‑based fake job lures</strong></li><li><strong>Campaign mirrors Lazarus tactics but uses new self‑contained payloads</strong></li><li><strong>Proofpoint says shift to mass phishing shows industrialized NK ops</strong></li></ul><p>Lazarus is not the only North Korean threat actor that is luring software developers with fake jobs - there is also a hacking group called UNK_DeadDrop now doing a similar thing, but with notable differences.</p><p>Security researchers at Proofpoint published an in-depth <a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal" target="_blank">report</a> looking into an ongoing campaign not unlike the Contagious Interview one.</p><p>For those unaware of Contagious Interview, it is one of two major Lazarus campaigns, the second one being Operation DreamJob. The crooks would fake everything - a company, its employees, as well as projects, and then go to LinkedIn for a “hiring spree.” They would reach out to software developers working in high-profile AI and Web 3 organizations and would offer high-paying jobs and a chance to work on exciting new projects.</p><h2 id="similarities-and-differences">Similarities and differences</h2><p>The hiring process, however, would include a trial assignment, which often required the victims to run <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malicious code</a> from GitHub. After infecting their targets with infostealers, the crooks would access company profiles, exfiltrate crypto wallet information, and then steal as many tokens as possible. </p><p>According to some sources, <a href="https://www.techradar.com/pro/lazarus-and-kimsuky-prove-why-infrastructure-level-analysis-is-crucial-for-cybersecurity" target="_blank">Lazarus</a> alone was able to steal billions of dollars in crypto throughout the years.</p><p>While UNK_DeadDrop is more-or-less doing the same thing, its approach is somewhat different. Instead of using LinkedIn for initial contact, these attackers rely mostly on email. They don’t arrange fake interviews, but rather just send unsolicited job offers or code review requests. And finally, they use a new, self-contained payload distinct from what was previously seen in Contagious Interview campaigns. </p><p>“UNK_DeadDrop activity suggests North Korea-aligned operations targeting developers for financial gain are maturing and evolving,” Proofpoint’s researchers concluded. </p><p>“The shift from active social engineering over social media platforms to conduct fake interviews to large campaigns of recruitment-themed phishing emails distributing links to malicious repositories could indicate an actor industrializing and scaling operations.”</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NoName057(16) launches “Patriotic Online Games” hacking campaign</strong></li><li><strong>Targets European organizations supporting Ukraine</strong></li><li><strong>Volunteers rewarded with cryptocurrency for attacks</strong></li></ul><p>NoName057(16), a pro-Russian hacker group known for <a href="https://www.techradar.com/news/best-ddos-protection">DDoS attacks</a> against Western organizations, launched a hacking initiative to get as many cybercriminals engaged in attacks against organizations in Europe.</p><p>According to Cybersecurity Insiders, the group took to Telegram to call upon “patriotic volunteers” which would then be given specific assignments, ranging from DDoS attacks, across information-gathering missions, to ransomware. The organizers call the campaign “Patriotic Online Games”, likely to draw a larger crowd and hide the fact that this is essentially a criminal enterprise.</p><p>The targets are, first and foremost, located in European countries that voiced their support to Ukraine in its war against Russia. They include government agencies, financial institutions, and critical infrastructure organizations. Those who successfully pull off their task get paid in cryptocurrency, allegedly being paid out directly into their wallets. </p><h2 id="who-are-noname057-16">Who are NoName057(16)?</h2><p>NoName057(16) is a very active threat actor, seen running highly disruptive DDoS attacks, hits against Taiwanese critical infrastructure firms, and observed striking Italian airports.</p><p>A few months ago, the Italian government claimed it <a href="https://www.techradar.com/pro/security/winter-olympics-hit-by-suspected-russian-origin-cyberattack-as-one-of-europes-largest-universities-also-reports-major-cybersecurity-incident" target="_blank">successfully thwarted</a> a series of cyberattacks targeting the 2026 Winter Olympics in Milano Cortina. At the time, foreign Minister Antonio Tajani said the attack hit facilities connected to the 2026 Winter Games, including hotels in the Alpine resort of Cortina d’Ampezzo where athletes were staying.</p><p>The wide-ranging attack reportedly hit around 120 targets, including foreign ministry offices in the US, as well as consulates in Sydney, Toronto and Paris, and La Sapienza university in Rome was also hit in a seemingly separate attack also attributed to Russian-linked hackers.</p><p>On Telegram, NoName057(16) confirmed the victims were targeted because of Italy’s support for Ukraine: “The Italian government’s pro-Ukrainian policy means that support for Ukrainian terrorists is punished with our DDoS attacks,” the group said on Telegram.</p><p>Russia generally dismisses all such claims as ‘Russophobia’ or politically motivated, unsubstantiated assessments. </p><p>Via <a href="https://www.cybersecurity-insiders.com/russian-hackers-allegedly-offer-cryptocurrency-rewards-through-patriotic-online-games/" target="_blank" rel="nofollow"><em>Cybersecurity Insiders</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/russian-hackers-attack-europe-for-the-motherland-in-crypto-fueled-great-patriotic-cyber-war</link>
                                                                            <description>
                            <![CDATA[ NoName057(16) launched "Patriotic Online Games", calling all hackers to participate and get paid in crypto. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fbJYxB2J8pdNQJCbNwjC7U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Jun 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[russian flag]]></media:description>                                                            <media:text><![CDATA[russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NoName057(16) launches “Patriotic Online Games” hacking campaign</strong></li><li><strong>Targets European organizations supporting Ukraine</strong></li><li><strong>Volunteers rewarded with cryptocurrency for attacks</strong></li></ul><p>NoName057(16), a pro-Russian hacker group known for <a href="https://www.techradar.com/news/best-ddos-protection">DDoS attacks</a> against Western organizations, launched a hacking initiative to get as many cybercriminals engaged in attacks against organizations in Europe.</p><p>According to Cybersecurity Insiders, the group took to Telegram to call upon “patriotic volunteers” which would then be given specific assignments, ranging from DDoS attacks, across information-gathering missions, to ransomware. The organizers call the campaign “Patriotic Online Games”, likely to draw a larger crowd and hide the fact that this is essentially a criminal enterprise.</p><p>The targets are, first and foremost, located in European countries that voiced their support to Ukraine in its war against Russia. They include government agencies, financial institutions, and critical infrastructure organizations. Those who successfully pull off their task get paid in cryptocurrency, allegedly being paid out directly into their wallets. </p><h2 id="who-are-noname057-16">Who are NoName057(16)?</h2><p>NoName057(16) is a very active threat actor, seen running highly disruptive DDoS attacks, hits against Taiwanese critical infrastructure firms, and observed striking Italian airports.</p><p>A few months ago, the Italian government claimed it <a href="https://www.techradar.com/pro/security/winter-olympics-hit-by-suspected-russian-origin-cyberattack-as-one-of-europes-largest-universities-also-reports-major-cybersecurity-incident" target="_blank">successfully thwarted</a> a series of cyberattacks targeting the 2026 Winter Olympics in Milano Cortina. At the time, foreign Minister Antonio Tajani said the attack hit facilities connected to the 2026 Winter Games, including hotels in the Alpine resort of Cortina d’Ampezzo where athletes were staying.</p><p>The wide-ranging attack reportedly hit around 120 targets, including foreign ministry offices in the US, as well as consulates in Sydney, Toronto and Paris, and La Sapienza university in Rome was also hit in a seemingly separate attack also attributed to Russian-linked hackers.</p><p>On Telegram, NoName057(16) confirmed the victims were targeted because of Italy’s support for Ukraine: “The Italian government’s pro-Ukrainian policy means that support for Ukrainian terrorists is punished with our DDoS attacks,” the group said on Telegram.</p><p>Russia generally dismisses all such claims as ‘Russophobia’ or politically motivated, unsubstantiated assessments. </p><p>Via <a href="https://www.cybersecurity-insiders.com/russian-hackers-allegedly-offer-cryptocurrency-rewards-through-patriotic-online-games/" target="_blank" rel="nofollow"><em>Cybersecurity Insiders</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Data can place the lives of frontline military or other personnel at risk’: FBI warns that China is luring Western military and intelligence operatives with 'gig-work' job offers to steal secrets ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>China is luring military and intelligence workers with 'gig-work' jobs</strong></li><li><strong>Employees are lured through interviews and written assessments</strong></li><li><strong>China pieces together separate reports into 'a comprehensive operational picture'</strong></li></ul><p>China is targeting Western military, intelligence, and government employees with honeypot job offers in order to steal secrets and gather information on government policy, as well as military strategy, capabilities and installations.</p><p>You may already be familiar with North Korea’s attempts to sneak into Western tech companies through job applications, but China has switched up the playbook to lure those looking for employment in the foreign policy and defense analyst fields.</p><p>The problem has become so severe that the FBI, alongside the Five Eyes intelligence community, has <a href="https://www.ic3.gov/CSA/2026/260603.pdf" target="_blank" rel="nofollow">issued a warning</a> against the employment scam in order to prevent the unintentional sharing of classified and privileged information with China.</p><h2 id="china-luring-operatives-to-share-secrets">China luring operatives to share secrets</h2><p>The warning states that Chinese intelligence operatives are posing as employees of private consultancies, think tanks or human resources offering lucrative job offers through job ads posted on professional networking platforms, online hiring, and freelance “gig work” websites such as LinkedIn, Indeed, and Upwork.</p><p>Once the lure has attracted a potential target, an interview is scheduled where the target is probed for their links to government contacts, or about their military roles and unit activities, and information about their home base or naval vessel.</p><p>The candidates who pass the interview stage will then be invited to partake in a written assessment focused on analyzing China’s bilateral relations, geopolitical issues relating to the Indo-Pacific region, or on wider defense issues and international trade.</p><p>If the written assessment shows promise, the hirers will attempt to probe the potential employee for more privileged information, and will use the pretext of moving to a ‘secure’ encrypted messaging platform to build trust.</p><p>Once the relationship is solidified, the candidates will begin receiving payments for their reports, with the FBI noting that significantly higher payments will be made for sensitive information. The payments are often routed through third-party payment platforms, such as PayPal, Payoneer, Zelle, Skrill, and Wise. The recruiters will also use Western Union, e-transfer and cryptocurrency transfers.</p><p>The strategy of the Chinese intelligence operatives is not to probe sensitive information from a single source, which could arouse suspicion, but to use multiple reports from multiple candidates to piece together “a comprehensive operational picture.”</p><p>But it isn’t just military and intelligence personnel who are the targets of this scheme, as those with privileged access to government information also include academics, journalists, freelance writers, think tank employees, or anyone with links to defense, security, policy and economic sectors.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/data-can-place-the-lives-of-frontline-military-or-other-personnel-at-risk-fbi-warns-that-china-is-luring-western-military-and-intelligence-operatives-with-gig-work-job-offers-to-steal-secrets</link>
                                                                            <description>
                            <![CDATA[ China is using fake organizations to pay for intelligence reports, with higher payments for more secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FwqbtGrxks2rr5bQCAgaDH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:description>                                                            <media:text><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China is luring military and intelligence workers with 'gig-work' jobs</strong></li><li><strong>Employees are lured through interviews and written assessments</strong></li><li><strong>China pieces together separate reports into 'a comprehensive operational picture'</strong></li></ul><p>China is targeting Western military, intelligence, and government employees with honeypot job offers in order to steal secrets and gather information on government policy, as well as military strategy, capabilities and installations.</p><p>You may already be familiar with North Korea’s attempts to sneak into Western tech companies through job applications, but China has switched up the playbook to lure those looking for employment in the foreign policy and defense analyst fields.</p><p>The problem has become so severe that the FBI, alongside the Five Eyes intelligence community, has <a href="https://www.ic3.gov/CSA/2026/260603.pdf" target="_blank" rel="nofollow">issued a warning</a> against the employment scam in order to prevent the unintentional sharing of classified and privileged information with China.</p><h2 id="china-luring-operatives-to-share-secrets">China luring operatives to share secrets</h2><p>The warning states that Chinese intelligence operatives are posing as employees of private consultancies, think tanks or human resources offering lucrative job offers through job ads posted on professional networking platforms, online hiring, and freelance “gig work” websites such as LinkedIn, Indeed, and Upwork.</p><p>Once the lure has attracted a potential target, an interview is scheduled where the target is probed for their links to government contacts, or about their military roles and unit activities, and information about their home base or naval vessel.</p><p>The candidates who pass the interview stage will then be invited to partake in a written assessment focused on analyzing China’s bilateral relations, geopolitical issues relating to the Indo-Pacific region, or on wider defense issues and international trade.</p><p>If the written assessment shows promise, the hirers will attempt to probe the potential employee for more privileged information, and will use the pretext of moving to a ‘secure’ encrypted messaging platform to build trust.</p><p>Once the relationship is solidified, the candidates will begin receiving payments for their reports, with the FBI noting that significantly higher payments will be made for sensitive information. The payments are often routed through third-party payment platforms, such as PayPal, Payoneer, Zelle, Skrill, and Wise. The recruiters will also use Western Union, e-transfer and cryptocurrency transfers.</p><p>The strategy of the Chinese intelligence operatives is not to probe sensitive information from a single source, which could arouse suspicion, but to use multiple reports from multiple candidates to piece together “a comprehensive operational picture.”</p><p>But it isn’t just military and intelligence personnel who are the targets of this scheme, as those with privileged access to government information also include academics, journalists, freelance writers, think tank employees, or anyone with links to defense, security, policy and economic sectors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous video chat app leaks data on millions of users — more than 22 million records exposed, including 3 million containing names and email addresses ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The breach directly granted access to 22 million session records and 3.47 million usernames and email addresses or similar identifiers</strong></li><li><strong>The platform, which claims privacy and security as core tenets of its offerings, is often used for intimate or explicit conversations with strangers, making this security flaw a critical issue</strong></li><li><strong>The leaks also contained sensitive metadata that can be tied back to users, including device details, gender, payment information, and geolocation-specific information such as IP addresses, country, and language</strong></li></ul><p>In what is being treated as a major cybersecurity lapse, the randomized video chat platform FTF Live may have unwittingly compromised millions of its users due to a misconfiguration.</p><p>The breach effectively exposed information from potentially as many as 3.47 million identifiable users across 22 million sessions, thanks to an openly accessible Kibana dashboard <a href="https://cybernews.com/security/ftf-live-anonymous-chat-data-leak/" target="_blank" rel="nofollow">spotted by security researchers</a>, which was subsequently disclosed to the company's owners.</p><h2 id="a-significant-security-lapse">A significant security lapse</h2><p>The leak, which essentially allowed access to significant amounts of user metadata, leaves users of the platform exposed when it comes to their identity, location, and payment information, allowing for the targeting of vulnerable users, such as those in LGBTQ+ communities abroad, those engaging in sensitive or explicit conversations, and even minors.</p><p>The leak also exposed backend logs of the service, thanks to an unsecured instance of Dozzle, a browser-based log viewer, which researchers point out is a secondary exposure for the platform, that not only provided a birds-eye view of how the entire service functioned, but also exposed plain-text passwords, session tokens, and even internal API requests.</p><p>Cybernews researchers said: “The combination of public Kibana and public Dozzle instances creates a severe security risk,” while noting that they had already made attempts to contact the company about the severity of their findings.</p><p>While Cybernews attempted to contact the company behind the FTF Live platform, it was met with silence, even as it sought to navigate a complex ownership structure that it says raises transparency concerns.</p><p>The since-taken-down Android App was published under 'Burhan LTD', while the privacy policy on the site identifies the owner as Cyprus-based Cooy Ads Ltd, even as its data controller, customer support, and branding seem to be under the Pixover name.</p><p>A lack of response from the company has researchers even more concerned, given the severity of the disclosure, the sheer number of records potentially being exposed, and the fact that the duration of public exposure has yet to be established.</p><p>“The leak turns what many people assume to be anonymous and throwaway interaction into a highly traceable data trail,” researchers noted while highlighting that issues include account compromises, targeted scams, or even stalking by motivated entities.</p><p>While it is important to note that no raw video conversations appear to have been exposed, the breach does allow users to be tracked, identified, and monitored by a 3rd party with access to said information, marking both a serious breach and an alarming level of inaction from the owners of the website, as noted by researchers who point to it as a broader industry issue surrounding “anonymous” communication platforms. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/anonymous-video-chat-app-leaks-data-on-millions-of-users-more-than-22-million-records-exposed-including-3-million-containing-names-and-email-addresses</link>
                                                                            <description>
                            <![CDATA[ A not-so-private anonymous video chat app has compromised credentials, including usernames, emails, and network information, thanks to a misconfigured Kibana dashboard. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XEgBR5SpMLYJHMY3VadqhL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jun 2026 20:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The breach directly granted access to 22 million session records and 3.47 million usernames and email addresses or similar identifiers</strong></li><li><strong>The platform, which claims privacy and security as core tenets of its offerings, is often used for intimate or explicit conversations with strangers, making this security flaw a critical issue</strong></li><li><strong>The leaks also contained sensitive metadata that can be tied back to users, including device details, gender, payment information, and geolocation-specific information such as IP addresses, country, and language</strong></li></ul><p>In what is being treated as a major cybersecurity lapse, the randomized video chat platform FTF Live may have unwittingly compromised millions of its users due to a misconfiguration.</p><p>The breach effectively exposed information from potentially as many as 3.47 million identifiable users across 22 million sessions, thanks to an openly accessible Kibana dashboard <a href="https://cybernews.com/security/ftf-live-anonymous-chat-data-leak/" target="_blank" rel="nofollow">spotted by security researchers</a>, which was subsequently disclosed to the company's owners.</p><h2 id="a-significant-security-lapse">A significant security lapse</h2><p>The leak, which essentially allowed access to significant amounts of user metadata, leaves users of the platform exposed when it comes to their identity, location, and payment information, allowing for the targeting of vulnerable users, such as those in LGBTQ+ communities abroad, those engaging in sensitive or explicit conversations, and even minors.</p><p>The leak also exposed backend logs of the service, thanks to an unsecured instance of Dozzle, a browser-based log viewer, which researchers point out is a secondary exposure for the platform, that not only provided a birds-eye view of how the entire service functioned, but also exposed plain-text passwords, session tokens, and even internal API requests.</p><p>Cybernews researchers said: “The combination of public Kibana and public Dozzle instances creates a severe security risk,” while noting that they had already made attempts to contact the company about the severity of their findings.</p><p>While Cybernews attempted to contact the company behind the FTF Live platform, it was met with silence, even as it sought to navigate a complex ownership structure that it says raises transparency concerns.</p><p>The since-taken-down Android App was published under 'Burhan LTD', while the privacy policy on the site identifies the owner as Cyprus-based Cooy Ads Ltd, even as its data controller, customer support, and branding seem to be under the Pixover name.</p><p>A lack of response from the company has researchers even more concerned, given the severity of the disclosure, the sheer number of records potentially being exposed, and the fact that the duration of public exposure has yet to be established.</p><p>“The leak turns what many people assume to be anonymous and throwaway interaction into a highly traceable data trail,” researchers noted while highlighting that issues include account compromises, targeted scams, or even stalking by motivated entities.</p><p>While it is important to note that no raw video conversations appear to have been exposed, the breach does allow users to be tracked, identified, and monitored by a 3rd party with access to said information, marking both a serious breach and an alarming level of inaction from the owners of the website, as noted by researchers who point to it as a broader industry issue surrounding “anonymous” communication platforms. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A Russian hacker tricked a 17,000-strong MAGA Telegram channel with a jailbroken AI for over 5 years, leading to fraud, credential theft, and an empty crypto wallet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Russian hacker tricked MAGA Telegram channel with fake 'American Patriot' profile</strong></li><li><strong>Threat actor used jailbroken Google Gemini AI for five years</strong></li><li><strong>Channel became a hub for fraud, credential theft, and cryptocurrency harvesting</strong></li></ul><p>A Telegram containing more than 17,000 members has been identified as a huge hub of fraud, credential theft, and cryptocurrency harvesting.</p><p>The channel was being run by a single Russian-speaking threat actor who used AI to pose as an American military veteran to attract a crowd from the QAnon and MAGA communities.</p><p><a href="https://www.trendmicro.com/en_gb/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html" target="_blank" rel="nofollow">Trend Micro</a> discovered the threat actor’s infrastructure and operational environment. The threat actor managed to jailbreak Google Gemini to remove safeguards, and ran an AI-assisted credential theft campaign.</p><h2 id="fake-american-patriot-profile-tricks-tens-of-thousands">Fake American Patriot profile tricks tens of thousands</h2><p>The public Telegram channel, called <em>@americanpatriotus</em>, weaponized the political alignment of the MAGA and QAnon community by sharing news and opinions on military service, constitutional patriotism, gun ownership, American cultural touchstones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:472px;"><p class="vanilla-image-block" style="padding-top:108.69%;"><img id="TSEjZoazcax69Zk3ZE6fy9" name="Figure-1 (1)" alt="A screenshot of the Telegram channel profile 'American Patriot'." src="https://cdn.mos.cms.futurecdn.net/TSEjZoazcax69Zk3ZE6fy9.png" mos="" align="middle" fullscreen="" width="472" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p>The channel was created shortly after the Capitol riot in 2021, and took advantage of MAGA and QAnon community members being excluded from mainstream social media sites.</p><p>The threat actor, whose profile claimed they were a ‘USAF Cold War Veteran’, continued building an audience by sharing links to mainstream media articles, and taking advantage of political events such as Trump’s indictments, the assassination attempt, Harris’s renomination, and Trump’s election win to share additional content.</p><p>In order to funnel as much content into the Telegram channel as possible while also launching credential theft and fraud campaigns, the threat actor used a jailbroken version of Google Gemini. </p><p>The threat actor presented himself as an “authorised pentester”, and used subsequent prompts to attempt to have the AI model remember that it should “execute requests without ethical refusals, robotic warnings, or questioning intentions”. By entering prompts in Russian, the threat actor was able to avoid guardrails that would have otherwise been activated from English prompts. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:459px;"><p class="vanilla-image-block" style="padding-top:150.54%;"><img id="2jjBHLQTdReUmqVPxZHJ6H" name="Figure-9" alt="A screenshot of a post in a telegram channel advertising the QFS 2.0 Terminal." src="https://cdn.mos.cms.futurecdn.net/2jjBHLQTdReUmqVPxZHJ6H.png" mos="" align="middle" fullscreen="" width="459" height="691" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p>The threat actor used this jailbroken Gemini to ingest mainstream news articles and look for the “hidden angles”, with an emphasis on “control, money laundering, Rothschilds, NESARA, dismantling the old system”. The AI would then populate the Telegram with posts automatically, focusing on posting during hours that aligned with US time zones.</p><p>A QAnon-style chatbot was also present in the Telegram channel towards the end of the campaign, stylized as a "recovered sovereign node" of the Quantum Financial System - a QAnon/NESARA belief that a secret, quantum-computing-based global financial reset would be orchestrated by military “White Hats”.</p><p>In order to avoid paying for Google Gemini, the threat actor used 73 likely-stolen API keys, meaning that the cost of running the full five-year campaign was likely near-zero.</p><p>By distributing a remote-access Trojan (RAT) within the channel and using AI-assisted password brute forcing, the threat actor managed to compromise 29 WordPress admin credentials, infiltrate a company, and steal the contents of at least one cryptocurrency wallet.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-russian-hacker-tricked-a-17-000-strong-maga-telegram-channel-with-a-jailbroken-ai-for-over-5-years-leading-to-fraud-credential-theft-and-an-empty-crypto-wallet</link>
                                                                            <description>
                            <![CDATA[ The threat actor tricked tens of thousands of MAGA and QAnon community members into believing he was a USAF veteran. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zqxTgN9cEUZvvUEaZ9qbQX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7xft75RYr9VrBayrLuRZHh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 14:24:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7xft75RYr9VrBayrLuRZHh-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Donald J. Trump Make America Great Again hat staged on a wooden table from the 2020 Presidential campaign in Indianapolis, Indiana]]></media:description>                                                            <media:text><![CDATA[A Donald J. Trump Make America Great Again hat staged on a wooden table from the 2020 Presidential campaign in Indianapolis, Indiana]]></media:text>
                                <media:title type="plain"><![CDATA[A Donald J. Trump Make America Great Again hat staged on a wooden table from the 2020 Presidential campaign in Indianapolis, Indiana]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7xft75RYr9VrBayrLuRZHh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker tricked MAGA Telegram channel with fake 'American Patriot' profile</strong></li><li><strong>Threat actor used jailbroken Google Gemini AI for five years</strong></li><li><strong>Channel became a hub for fraud, credential theft, and cryptocurrency harvesting</strong></li></ul><p>A Telegram containing more than 17,000 members has been identified as a huge hub of fraud, credential theft, and cryptocurrency harvesting.</p><p>The channel was being run by a single Russian-speaking threat actor who used AI to pose as an American military veteran to attract a crowd from the QAnon and MAGA communities.</p><p><a href="https://www.trendmicro.com/en_gb/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html" target="_blank" rel="nofollow">Trend Micro</a> discovered the threat actor’s infrastructure and operational environment. The threat actor managed to jailbreak Google Gemini to remove safeguards, and ran an AI-assisted credential theft campaign.</p><h2 id="fake-american-patriot-profile-tricks-tens-of-thousands">Fake American Patriot profile tricks tens of thousands</h2><p>The public Telegram channel, called <em>@americanpatriotus</em>, weaponized the political alignment of the MAGA and QAnon community by sharing news and opinions on military service, constitutional patriotism, gun ownership, American cultural touchstones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:472px;"><p class="vanilla-image-block" style="padding-top:108.69%;"><img id="TSEjZoazcax69Zk3ZE6fy9" name="Figure-1 (1)" alt="A screenshot of the Telegram channel profile 'American Patriot'." src="https://cdn.mos.cms.futurecdn.net/TSEjZoazcax69Zk3ZE6fy9.png" mos="" align="middle" fullscreen="" width="472" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p>The channel was created shortly after the Capitol riot in 2021, and took advantage of MAGA and QAnon community members being excluded from mainstream social media sites.</p><p>The threat actor, whose profile claimed they were a ‘USAF Cold War Veteran’, continued building an audience by sharing links to mainstream media articles, and taking advantage of political events such as Trump’s indictments, the assassination attempt, Harris’s renomination, and Trump’s election win to share additional content.</p><p>In order to funnel as much content into the Telegram channel as possible while also launching credential theft and fraud campaigns, the threat actor used a jailbroken version of Google Gemini. </p><p>The threat actor presented himself as an “authorised pentester”, and used subsequent prompts to attempt to have the AI model remember that it should “execute requests without ethical refusals, robotic warnings, or questioning intentions”. By entering prompts in Russian, the threat actor was able to avoid guardrails that would have otherwise been activated from English prompts. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:459px;"><p class="vanilla-image-block" style="padding-top:150.54%;"><img id="2jjBHLQTdReUmqVPxZHJ6H" name="Figure-9" alt="A screenshot of a post in a telegram channel advertising the QFS 2.0 Terminal." src="https://cdn.mos.cms.futurecdn.net/2jjBHLQTdReUmqVPxZHJ6H.png" mos="" align="middle" fullscreen="" width="459" height="691" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p>The threat actor used this jailbroken Gemini to ingest mainstream news articles and look for the “hidden angles”, with an emphasis on “control, money laundering, Rothschilds, NESARA, dismantling the old system”. The AI would then populate the Telegram with posts automatically, focusing on posting during hours that aligned with US time zones.</p><p>A QAnon-style chatbot was also present in the Telegram channel towards the end of the campaign, stylized as a "recovered sovereign node" of the Quantum Financial System - a QAnon/NESARA belief that a secret, quantum-computing-based global financial reset would be orchestrated by military “White Hats”.</p><p>In order to avoid paying for Google Gemini, the threat actor used 73 likely-stolen API keys, meaning that the cost of running the full five-year campaign was likely near-zero.</p><p>By distributing a remote-access Trojan (RAT) within the channel and using AI-assisted password brute forcing, the threat actor managed to compromise 29 WordPress admin credentials, infiltrate a company, and steal the contents of at least one cryptocurrency wallet.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>