<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-SG"
                       href="https://www.techradar.com/sg/feeds/tag/computing-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar SG in Computing-security ]]></title>
                <link>https://www.techradar.com/sg/computing/computing-security</link>
        <description><![CDATA[ All the latest computing-security content from the TechRadar  SG team ]]></description>
                                    <lastBuildDate>Tue, 08 Sep 2026 15:35:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-365-users-hit-by-two-major-threat-campaigns-fake-it-calls-and-phishing-emails-target-users-across-the-world</link>
                                                                            <description>
                            <![CDATA[ BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and MFA codes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C6BxVw2HaDLYXxNeeyT4HQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png">
                                                            <media:credit><![CDATA[Currys]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two major security flaws are affecting more than six million WordPress websites ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/two-major-security-flaws-are-affecting-more-than-six-million-wordpress-websites</link>
                                                                            <description>
                            <![CDATA[ Patches are available, so WordPress users should hurry up and apply them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ECcHJPTq7j6ouvCBPkCyJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 tells businesses to get ready for quantum cybersecurity threats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/g7-tells-businesses-to-get-ready-for-quantum-cybersecurity-threats</link>
                                                                            <description>
                            <![CDATA[ Organizations late to the migration could lose contracting opportunities, G7 warns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2ZkfdmUW73vAcJc8nb3TLL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices — and leaders aren't happy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-military-troops-can-still-be-hit-by-targeted-attacks-despite-disabling-ad-tracking-on-their-devices-and-leaders-arent-happy</link>
                                                                            <description>
                            <![CDATA[ Government-issued devices are safe - but what about private devices? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qxo8CGkgGxxCnCDCgsK3sd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NATALIA KOLESNIKOVA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Belarusian border guard with a service dog]]></media:description>                                                            <media:text><![CDATA[A Belarusian border guard with a service dog]]></media:text>
                                <media:title type="plain"><![CDATA[A Belarusian border guard with a service dog]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware hackers dump 1.4 million stolen records from German government ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-hackers-dump-1-4-million-stolen-records-from-german-government</link>
                                                                            <description>
                            <![CDATA[ This is an "extremely serious crime" and an attack on Berlin, the government says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sTAtVCtttosNejBRf3aDA4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:35:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-invisible-unicode-characters-to-sneak-phishing-lures-into-emails</link>
                                                                            <description>
                            <![CDATA[ A technique used in prompt injection attacks has made it into phishing, Microsoft has warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kpbZtKyjta2kiuQw3KPbBZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Save up to 50% off Keeper plans this September — protect your passwords with half price Personal plans, and a third-off Business plans ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/save-up-to-50-percent-off-keeper-plans-this-september-protect-your-passwords-with-half-price-personal-plans-and-a-third-off-business-plans</link>
                                                                            <description>
                            <![CDATA[ Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A3tb9XngX6pNeDLcj6Au2h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:17:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is there so much worry about OpenAI Astra, and what issues could ‘recurrent depth’ reasoning cause? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-there-so-much-worry-about-openai-astra-and-what-issues-could-recurrent-depth-reasoning-cause-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ As OpenAI unveils GPT-6 Astra, cybersecurity experts question whether the model's 'recurrent depth' reasoning was properly tested. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C8dxY7YkHdtYyEPzyEiovn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 05 Sep 2026 13:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 09:36:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google patches multiple browser bugs including one that was under active exploitation — so update now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-patches-multiple-browser-bugs-including-one-that-was-under-active-exploitation-so-update-now</link>
                                                                            <description>
                            <![CDATA[ Google did not share the details about the bug being actively used. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PWhL6n866rriJHC4C6KTWa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 19:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI warns about how good Astra model is at cracking cybersecurity, releases it anyway because it took 'years of research and big bets' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-warns-about-how-good-astra-model-is-at-cracking-cybersecurity-releases-it-anyway-because-it-took-years-of-research-and-big-bets</link>
                                                                            <description>
                            <![CDATA[ GPT-6 Astra was paused a month ago for triggering safety protocols and now it's being slowly rolled out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JV7weBTmHEVs8GrqeHEVAE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why did FulcrumSec hackers try to extort Manchester Airports Group, and what happens now the data is leaked? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-did-fulcrumsec-hackers-try-to-extort-manchester-airports-group-and-what-happens-now-the-data-is-leaked-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ After hackers failed to extort Manchester Airports Group and posted the data of nearly 9 million people online, we asked the experts what's really going on. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fRCxPaa9De9wPUPVGxjDbh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 14:57:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-patches-three-critical-vulnerabilities-as-part-of-comprehensive-internal-security-review</link>
                                                                            <description>
                            <![CDATA[ A total of eight flaws were fixed, none of which were exploited in the wild. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NwtFJ9WsAyxAmKVur5Dra9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Valriya Zankovych]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco]]></media:description>                                                            <media:text><![CDATA[Cisco]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI puts its money where its mouth is, offers $1 billion in AI credits to cyber defenders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-puts-its-money-where-its-mouth-is-offers-usd1-billion-in-ai-credits-to-cyber-defenders</link>
                                                                            <description>
                            <![CDATA[ Want to use Daybreak but cannot afford it? You can now apply for a subsidy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t2rShP2332cHQ4q6yU7QA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/SPOA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo on a smartphone.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/it-helpdesk-impersonation-hits-microsoft-teams-once-again-with-the-hackers-hiding-their-activity-within-legitimate-tools</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing scam campaign starting in Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAnBBRikxHpmReRRcBoNhU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 16:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Collaboration in an office.]]></media:text>
                                <media:title type="plain"><![CDATA[Collaboration in an office.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/clicking-allow-on-a-google-and-microsoft-permission-screens-could-give-hackers-access-to-your-entire-account-fbi-warns</link>
                                                                            <description>
                            <![CDATA[ OAuth consent phishing is a thing and the FBI is worried. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pWbGg4PydfXBEVQetdDJBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay/Tumisu]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/thomson-reuters-hit-by-cyberattack-that-saw-court-documents-across-11-states-accessed-by-a-hacker</link>
                                                                            <description>
                            <![CDATA[ A threat actor accessed C-Track files, compromised a cloud environment, and accessed court records across 11 states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m8aiHByXqAA9YTCGGbFHxY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only one in five UK CEOs say their cyber insurance will cover the full cost of a cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/only-one-in-five-uk-ceos-say-their-cyber-insurance-will-cover-the-full-cost-of-a-cyberattack</link>
                                                                            <description>
                            <![CDATA[ New data has revealed that only one in five CEOs expect full coverage from their cyber insurance policy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ3r6t6Y6FWyxjoMbJbwM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/2-8-million-people-affected-by-data-breach-at-baylor-genetics-testing-and-diagnostic-firm</link>
                                                                            <description>
                            <![CDATA[ Business continued as usual, although employees and patients lost plenty of sensitive data in the incident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">asYqA3pQDCzhjPh7qcTguQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lords call for a 'kill switch' on powerful AI systems used in the United Kingdom ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/lords-call-for-a-kill-switch-on-powerful-ai-systems-used-in-the-united-kingdom</link>
                                                                            <description>
                            <![CDATA[ They believe the UK needs a "vital safety net" to only be used as a last resort. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iicNmwrFCpfHr7U9X2LbK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:10:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ai-is-getting-closer-to-being-able-to-exploit-ot-and-thats-very-bad-news-for-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ The situation is not disastrous just yet, but it's definitely time to start paying attention, Forescout hints. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LgfjTgBPhj45riESsCbqxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 20:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts</strong></li><li><strong>Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact</strong></li><li><strong>Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup</strong></li></ul><p>Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:</p><p>Earlier this week, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Dropbox</a> started notifying affected individuals about the incident. In the data breach notification email, the company explains:</p><p>“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”</p><h2 id="fixing-the-flaw">Fixing the flaw</h2><p>In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.</p><p>The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. </p><p>The vulnerability has since been addressed, and further steps taken to protect <a href="https://www.techradar.com/reviews/dropbox-cloud-storage-review" target="_blank">Dropbox</a> users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID. </p><p>“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts.</p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.</p><p>"The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”</p><p><em>Via </em><a href="https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/over-5-000-dropbox-accounts-have-been-hacked-and-the-attackers-only-needed-an-email-address</link>
                                                                            <description>
                            <![CDATA[ A bug in Lenovo's ID verification system made it possible to access Dropbox accounts, but the bug has since been fixed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VtAcT6B5XAjE9cei3xVEt7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dropbox logo is seen on a smartphone.]]></media:description>                                                            <media:text><![CDATA[Dropbox logo is seen on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Dropbox logo is seen on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts</strong></li><li><strong>Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact</strong></li><li><strong>Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup</strong></li></ul><p>Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:</p><p>Earlier this week, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Dropbox</a> started notifying affected individuals about the incident. In the data breach notification email, the company explains:</p><p>“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”</p><h2 id="fixing-the-flaw">Fixing the flaw</h2><p>In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.</p><p>The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. </p><p>The vulnerability has since been addressed, and further steps taken to protect <a href="https://www.techradar.com/reviews/dropbox-cloud-storage-review" target="_blank">Dropbox</a> users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID. </p><p>“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts.</p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.</p><p>"The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”</p><p><em>Via </em><a href="https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A malware installer posing as a legitimate download service is infecting brands across almost every industry — Microsoft Edge, Razer, Kaspersky and more actively imitated ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns Chinese group </strong><em><strong>Silver Fox</strong></em><strong> spoofed download sites for major tech brands</strong></li><li><strong>Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery</strong></li><li><strong>Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection</strong></li></ul><p>Cybercriminals are spoofing some of the world’s most popular technology and software companies in an attempt to infect their targets with dangerous <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoors</a>. This is according to security researchers from Microsoft, who warned about the ongoing campaign in an in-depth report published earlier this week.</p><p>Microsoft said it discovered an ongoing campaign in which Chinese hackers (presumably Silver Fox, AKA Yinhu) were creating fraudulent download pages for some of the world’s most popular tech and software companies, including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and many others. </p><p>Victim organizations looking to download software built by these companies end up downloading a weaponized version that works primarily as a backdoor. This implant allows the attackers a foothold from which they can maintain access and send/receive messages.</p><h2 id="how-to-defend-against-silver-fox">How to defend against Silver Fox</h2><p>Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling a number of update-related services.</p><p>It also deletes backups, and allows the attackers to deploy further payloads. </p><p>Victims are primarily Chinese organizations, although the attackers do seem to be casting a rather wide net, Microsoft suggests. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education. </p><p>Microsoft says its Defender product “detected and disrupted” the activity across multiple stages of the attack, “including automated containment through attack disruption.” </p><p>Still, to defend against Silver Fox’s latest shenanigans, Microsoft advises organizations enforce tamper Protection which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. </p><p>It also suggests defenders hunt for “behavior, not file names”, set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow. The full list of Indicators of Compromise (IoC) can be found on <a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/#campaign-scope-and-targeting" target="_blank" rel="nofollow">this link</a>, as well.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-malware-installer-posing-as-a-legitimate-download-service-is-infecting-brands-across-almost-every-industry-microsoft-edge-razer-kaspersky-and-more-actively-imitated</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing campaign abusing dozens of popular technology and software firms. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m7u3mzYmbdzPaHpThQaPrh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns Chinese group </strong><em><strong>Silver Fox</strong></em><strong> spoofed download sites for major tech brands</strong></li><li><strong>Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery</strong></li><li><strong>Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection</strong></li></ul><p>Cybercriminals are spoofing some of the world’s most popular technology and software companies in an attempt to infect their targets with dangerous <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoors</a>. This is according to security researchers from Microsoft, who warned about the ongoing campaign in an in-depth report published earlier this week.</p><p>Microsoft said it discovered an ongoing campaign in which Chinese hackers (presumably Silver Fox, AKA Yinhu) were creating fraudulent download pages for some of the world’s most popular tech and software companies, including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and many others. </p><p>Victim organizations looking to download software built by these companies end up downloading a weaponized version that works primarily as a backdoor. This implant allows the attackers a foothold from which they can maintain access and send/receive messages.</p><h2 id="how-to-defend-against-silver-fox">How to defend against Silver Fox</h2><p>Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling a number of update-related services.</p><p>It also deletes backups, and allows the attackers to deploy further payloads. </p><p>Victims are primarily Chinese organizations, although the attackers do seem to be casting a rather wide net, Microsoft suggests. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education. </p><p>Microsoft says its Defender product “detected and disrupted” the activity across multiple stages of the attack, “including automated containment through attack disruption.” </p><p>Still, to defend against Silver Fox’s latest shenanigans, Microsoft advises organizations enforce tamper Protection which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. </p><p>It also suggests defenders hunt for “behavior, not file names”, set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow. The full list of Indicators of Compromise (IoC) can be found on <a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/#campaign-scope-and-targeting" target="_blank" rel="nofollow">this link</a>, as well.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Crowdstrike and law enforcement disrupted </strong><em><strong>Sality</strong></em><strong>, a peer‑to‑peer botnet active since 2003</strong></li><li><strong>Botnet spread malware and clipboard hijacker </strong><em><strong>EggJagger</strong></em><strong>, stealing $150K in cryptocurrency</strong></li><li><strong>Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others</strong></li></ul><p>Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. </p><p>Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.</p><p>Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.</p><h2 id="sinkholing-the-botnet">Sinkholing the botnet</h2><p>Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. </p><p>According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. </p><p>The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.</p><p>Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.</p><p>The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. </p><p>“We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-botnet-running-for-23-years-with-over-15-000-endpoints-has-finally-been-shut-down-by-law-enforcement-and-crowdstrike</link>
                                                                            <description>
                            <![CDATA[ Crowdstrike and friends sinkholed thousands of Sality's endpoints rendering the botnet useless. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hYVMqEnoH4kyZxtDMa2hsT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:description>                                                            <media:text><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Crowdstrike and law enforcement disrupted </strong><em><strong>Sality</strong></em><strong>, a peer‑to‑peer botnet active since 2003</strong></li><li><strong>Botnet spread malware and clipboard hijacker </strong><em><strong>EggJagger</strong></em><strong>, stealing $150K in cryptocurrency</strong></li><li><strong>Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others</strong></li></ul><p>Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. </p><p>Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.</p><p>Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.</p><h2 id="sinkholing-the-botnet">Sinkholing the botnet</h2><p>Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. </p><p>According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. </p><p>The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.</p><p>Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.</p><p>The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. </p><p>“We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients</strong></li><li><strong>Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients</strong></li><li><strong>No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026</strong></li></ul><p>American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.</p><p>In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is. </p><p>Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Amazon Web Services</a> (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18. </p><h2 id="losing-personally-identifiable-information">Losing personally identifiable information</h2><p>According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.</p><p>In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. </p><p>This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.</p><p>Aesto Health is now offering credit monitoring and <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection</a> services to everyone affected by the breach.</p><p>This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on <a href="https://www.techradar.com/pro/security/2-6-million-dentaquest-accounts-exposed-by-data-breach-shinyhunters-claim-234gb-of-data-stolen" target="_blank">DentaQuest</a> that exposed 15 million records.</p><p><em>Via </em><a href="https://www.hipaajournal.com/aesto-health-data-breach/" target="_blank" rel="nofollow"><em>HIPAA Journal</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/more-than-9-5-million-patients-affected-by-aesto-health-breach-names-ssns-financial-details-health-records-and-more-stolen</link>
                                                                            <description>
                            <![CDATA[ More than two dozen of Aesto's clients affected by the December 2025 cyberincident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aVyqZKE4ytmNY5xtknGbA6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 12:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients</strong></li><li><strong>Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients</strong></li><li><strong>No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026</strong></li></ul><p>American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.</p><p>In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is. </p><p>Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Amazon Web Services</a> (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18. </p><h2 id="losing-personally-identifiable-information">Losing personally identifiable information</h2><p>According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.</p><p>In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. </p><p>This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.</p><p>Aesto Health is now offering credit monitoring and <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection</a> services to everyone affected by the breach.</p><p>This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on <a href="https://www.techradar.com/pro/security/2-6-million-dentaquest-accounts-exposed-by-data-breach-shinyhunters-claim-234gb-of-data-stolen" target="_blank">DentaQuest</a> that exposed 15 million records.</p><p><em>Via </em><a href="https://www.hipaajournal.com/aesto-health-data-breach/" target="_blank" rel="nofollow"><em>HIPAA Journal</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records</strong></li><li><strong>Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M</strong></li><li><strong>Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed</strong></li></ul><p>Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">extortion</a> group.</p><p>McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”. </p><p>The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack. </p><h2 id="boston-scientific-works-on-restoring-systems">Boston Scientific works on restoring systems</h2><p>The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation. </p><p>Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems. </p><p>“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”</p><p><a href="https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations" target="_blank">Boston Scientific is yet to name ShinyHunters as the perpetrators</a>, and the group has not yet publicly claimed responsibility for the attack.</p><p><em>Via </em><a href="" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-healthcare-giants-hit-by-data-breaches-affecting-patient-records-social-security-numbers-and-even-implanted-cardiac-devices</link>
                                                                            <description>
                            <![CDATA[ Boston Scientific and McKesson are working on restoring services after being struck by disruptive cyberattacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GDuLq4JqbV564wt5k96bSV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 21:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records</strong></li><li><strong>Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M</strong></li><li><strong>Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed</strong></li></ul><p>Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">extortion</a> group.</p><p>McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”. </p><p>The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack. </p><h2 id="boston-scientific-works-on-restoring-systems">Boston Scientific works on restoring systems</h2><p>The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation. </p><p>Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems. </p><p>“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”</p><p><a href="https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations" target="_blank">Boston Scientific is yet to name ShinyHunters as the perpetrators</a>, and the group has not yet publicly claimed responsibility for the attack.</p><p><em>Via </em><a href="" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-routers-are-being-turned-into-surveillance-vantage-points-to-hoover-up-data-on-trusted-networks-and-its-all-thanks-to-this-new-malware</link>
                                                                            <description>
                            <![CDATA[ Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ktXPBkae4A3uwRF8jyucDd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korea expands fraudulent job resumes to target marketing, sales, and medical sector ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress reports DPRK job seekers expanding beyond tech into healthcare, sales, and marketing</strong></li><li><strong>North Koreans use stolen identities, forged documents, AI tools, and proxies to bypass detection</strong></li><li><strong>Campaign dubbed “IT worker scheme” continues, posing sanctions risks and unique detection challenges</strong></li></ul><p>North Koreans looking to get hired by western companies are no longer focused exclusively on tech companies. According to security researchers Huntress, they have started applying for jobs in healthcare, sales, and marketing.</p><p>For US companies, employing North Koreans is prohibited under US sanctions, and the US government specifically warns about hiring IT workers from DPRK. As a result, these individuals are engaging in all sorts of fraudulent behavior to trick their potential employers and get hired. </p><p>That includes stealing other people’s identities, forging documents, and using pre-recorded or AI generated videos during calls and interviews. They’re also using ChatGPT to draft answers to questions and communicate without raising any alarms. Furthermore, they are deploying proxies and VPNs, often connecting to computers on “hardware farms” in China, and using personal, non-resident banking accounts to get paid.</p><h2 id="it-worker-scheme">IT worker scheme</h2><p>"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.</p><p>This is a campaign that’s been ongoing for years. Researchers call it the “IT worker scheme” and while some argue the scammers are using their earned salary to further North Korea’s weapons program, there is no evidence to point in that direction. For all we know, they might actually be desperate for a job - they’re just not allowed to do it remotely.</p><p>In its latest report, Huntress says it saw three people in an Australian healthcare company that turned out to be North Koreans impersonating the Chinese. It also saw an unnamed financial services firm whose employees used software that allowed them to work remotely through devices hosted on laptop farms.</p><p>Finally, it investigated a case of a sales and marketing employee using a <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">stolen identity</a>. The worker allegedly used the personal details of a legitimate individual (name, birth date, location) which had been published online by law enforcement following that person’s arrest. At the same time, they were using their own face during the hiring process. </p><p><em>Via </em><a href="https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/north-korea-expands-fraudulent-job-resumes-to-target-marketing-sales-and-medical-sector</link>
                                                                            <description>
                            <![CDATA[ North Koreans are going to great lengths to get hired in the west, even if it means faking absolutely everything. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SmYDbBgwpxbsMGLsENbYsD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 16:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress reports DPRK job seekers expanding beyond tech into healthcare, sales, and marketing</strong></li><li><strong>North Koreans use stolen identities, forged documents, AI tools, and proxies to bypass detection</strong></li><li><strong>Campaign dubbed “IT worker scheme” continues, posing sanctions risks and unique detection challenges</strong></li></ul><p>North Koreans looking to get hired by western companies are no longer focused exclusively on tech companies. According to security researchers Huntress, they have started applying for jobs in healthcare, sales, and marketing.</p><p>For US companies, employing North Koreans is prohibited under US sanctions, and the US government specifically warns about hiring IT workers from DPRK. As a result, these individuals are engaging in all sorts of fraudulent behavior to trick their potential employers and get hired. </p><p>That includes stealing other people’s identities, forging documents, and using pre-recorded or AI generated videos during calls and interviews. They’re also using ChatGPT to draft answers to questions and communicate without raising any alarms. Furthermore, they are deploying proxies and VPNs, often connecting to computers on “hardware farms” in China, and using personal, non-resident banking accounts to get paid.</p><h2 id="it-worker-scheme">IT worker scheme</h2><p>"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.</p><p>This is a campaign that’s been ongoing for years. Researchers call it the “IT worker scheme” and while some argue the scammers are using their earned salary to further North Korea’s weapons program, there is no evidence to point in that direction. For all we know, they might actually be desperate for a job - they’re just not allowed to do it remotely.</p><p>In its latest report, Huntress says it saw three people in an Australian healthcare company that turned out to be North Koreans impersonating the Chinese. It also saw an unnamed financial services firm whose employees used software that allowed them to work remotely through devices hosted on laptop farms.</p><p>Finally, it investigated a case of a sales and marketing employee using a <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">stolen identity</a>. The worker allegedly used the personal details of a legitimate individual (name, birth date, location) which had been published online by law enforcement following that person’s arrest. At the same time, they were using their own face during the hiring process. </p><p><em>Via </em><a href="https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922</strong></li><li><strong>Attack spoofed tax authority emails in China and India, delivering PackClient installer</strong></li><li><strong>RAT offers advanced features; researchers warn broader adoption likely beyond Asia</strong></li></ul><p>For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.</p><p>According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.</p><p>Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.</p><h2 id="picking-up-the-malware">Picking up the malware</h2><p>Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.</p><p>The “paperwork”, however, was nothing more than the PackClient installer.</p><p>In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.</p><p>However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK. </p><p>Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.</p><p>“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="nofollow">IoC</a>), in case you’re suspicious of an infection.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/careful-when-filing-your-taxes-this-new-packclient-malware-is-hitting-global-firms-via-tax-audit-lures</link>
                                                                            <description>
                            <![CDATA[ The Chinese are using a tax lure to deploy a new RAT and take over victim devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9WYHdQcCnqkSjx9Tu2W5ML</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 15:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Someone using forms to pay their taxes.]]></media:description>                                                            <media:text><![CDATA[Someone using forms to pay their taxes.]]></media:text>
                                <media:title type="plain"><![CDATA[Someone using forms to pay their taxes.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922</strong></li><li><strong>Attack spoofed tax authority emails in China and India, delivering PackClient installer</strong></li><li><strong>RAT offers advanced features; researchers warn broader adoption likely beyond Asia</strong></li></ul><p>For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.</p><p>According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.</p><p>Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.</p><h2 id="picking-up-the-malware">Picking up the malware</h2><p>Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.</p><p>The “paperwork”, however, was nothing more than the PackClient installer.</p><p>In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.</p><p>However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK. </p><p>Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.</p><p>“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="nofollow">IoC</a>), in case you’re suspicious of an infection.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs</strong></li><li><strong>Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant</strong></li><li><strong>Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks</strong></li></ul><p>Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>.</p><p>Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack. </p><p>“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.</p><h2 id="look-for-lateral-movement">Look for lateral movement</h2><p>Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.</p><p>It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network. </p><p>In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement. </p><p>“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”</p><p>Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:</p><p>“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-clickfix-campaign-can-deploy-powerful-multi-stage-malware-directly-through-windows-terminal-and-powershell</link>
                                                                            <description>
                            <![CDATA[ Microsoft is calling it "TerminalFix" and says it is used to deliver "complex, multi-line scripts". ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XjNSaZ8GDPSYkPbNvjqpdU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 09:54:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs</strong></li><li><strong>Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant</strong></li><li><strong>Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks</strong></li></ul><p>Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>.</p><p>Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack. </p><p>“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.</p><h2 id="look-for-lateral-movement">Look for lateral movement</h2><p>Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.</p><p>It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network. </p><p>In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement. </p><p>“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”</p><p>Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:</p><p>“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How did Iran manage to knock a UK power generator offline for four days, and what does it mean for other critical infrastructure? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Just days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US, a UK power generation plant was taken offline for four days after a cyberattack.</p><p>The attack has been attributed to Iran, which has stepped up its offensive cyber warfare efforts since the US and Israel began conducting strikes in February 2026. These cyberattacks have been largely focused on the US and its allies.</p><p>A UK government spokesperson responded to the attack, stating, “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards,” (via <a href="https://www.cnbc.com/2026/08/23/small-uk-power-plant-shut-down-after-iran-linked-cyberattack-report.html"><em>CNBC</em></a>).</p><h2 id="the-wider-impact-for-critical-infrastructure">The wider impact for critical infrastructure</h2><p>While the attack may have only targeted a ‘small-scale energy generator’, it shows that state-sponsored groups are actively attempting to disrupt UK energy production in any way they can, regardless of how much power it provides.</p><p>As has been made abundantly clear in the US, much of the world’s major critical infrastructure relies on small network-enabled operation technology (OT) components.</p><p>If OT devices have passed their end-of-life and no longer receive software updates, or have simply been misconfigured, these devices can show up on the internet to a hacker looking for a way into a protected network.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The UK has taken very careful steps to shield these devices from the internet to prevent them being used to access critical infrastructure, but it only takes a single internet-facing OT to cause issues.</p><p>Following the aftermath of the attack, the UK’s National Cyber Security Centre has issued new guidance on protecting OT devices from state-sponsored threats.</p><p>In its <a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices" target="_blank" rel="nofollow">guidance</a>, the NCSC said “the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.”</p><p>So what do the experts think the attack means for critical infrastructure, the UK, and the wider world?</p><h3 class="article-body__section" id="section-expert-perspectives-on-uk-powerplant-attack"><span>Expert perspectives on UK powerplant attack</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>Attackers don’t care whether an energy operator is large enough to meet a reporting threshold. If it can be disrupted, it can be targeted. The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.</em></p><div><blockquote><p>Why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</p></blockquote></div><p><em>That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</em></p><p><em>There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.</em></p><p><em>Critical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.</em></p><p><em>The real measure of cyber resilience is no longer simply whether you can prevent an intrusion. It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis</em></p><ul><li><strong>Graeme Stewart, head of public sector, Check Point:</strong></li></ul><p><em>This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days. That should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside.</em></p><div><blockquote><p>The far more serious point is what the attackers appear to have demonstrated: an ability to get inside</p></blockquote></div><p><em>UK energy infrastructure and stop it working. We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on. Britain’s Critical National Infrastructure underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another. A serious attack on one part of that ecosystem has the potential to cause disruption far beyond the original target.</em></p><p><em>For most Brits, the Iran conflict is happening thousands of miles away and cyber warfare probably still conjures up images of stolen passwords, leaked data and companies being held to ransom. The prospect of a hostile state being able to reach into the infrastructure beneath our everyday lives changes that dramatically, because suddenly an international conflict has a potential route to our front doors through the power we use, the water we depend on and the networks that keep us connected. We also need to consider whether causing widespread disruption was ever the objective here. If this attack was intended to demonstrate that Iranian-linked hackers can penetrate UK infrastructure and cause real-world consequences, then the significance isn't measured by the size of the generator they managed to shut down, but by what they have demonstrated may be possible.</em></p><p><em>The question now has to be whether Britain is genuinely ready if something more serious follows. We cannot build our resilience around the assumption that every attacker will be stopped at the door, particularly when we have just seen reports of one getting through. Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread. Cybersecurity is rapidly becoming about something much bigger than protecting information. It is about protecting the systems that allow a modern country to function and finding out how resilient those systems are during a major attack would be far too late</em></p><ul><li><strong>Matt Caswell, Executive Director, OpenSSL Foundation and Principal Software Engineer:</strong></li></ul><p><em>An attack that can take part of the UK’s power infrastructure offline is a reminder that cyber resilience is about more than protecting the organisation at the front of the incident. We also need to understand the technology and dependencies sitting underneath critical services.</em></p><div><blockquote><p>Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on.</p></blockquote></div><p><em>Modern infrastructure contains layers of software from different suppliers and open-source projects. Organisations need enough visibility to know which dependencies really matter before an attack happens, so they can understand their exposure and respond quickly when something goes wrong.</em></p><p><em>For the UK, this is also a wider resilience question. Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on. That needs to be part of the conversation about how we protect essential services.</em></p><ul><li><strong>Tim Williams, CEO, Quod Orbis:</strong></li></ul><p><em>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened. The real warning is that a hostile actor was able to disrupt a piece of the UK’s energy infrastructure in the first place.</em></p><div><blockquote><p>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened.</p></blockquote></div><p><em>Avoiding a major outage is all well and good, but it shouldn’t be seen as the success metric for true cyber resilience. The real measure of cyber resilience isn't whether an organisation has controls documented in a framework. It's whether it can continuously demonstrate that those controls are working when they matter most, identifying control weaknesses before they are exploited and become operational incidents.</em></p><p><em>As geopolitical tensions increase, organisations need to assume that cyber attacks are potential business continuity events and ones that are capable of impacting far more than the businesses themselves. Critical national infrastructure such as electricity, power and water are likely to be the targets for more attacks so resilience will really depend on knowing, in real time, whether the controls designed to protect critical operations are actually working, and having clear accountability when they are not.</em></p><p><em>Reactive incident response is important but it’s not enough. Continuous assurance needs to become part of how organisations manage operational resilience, particularly as state-linked actors increasingly look for ways to exploit the digital systems underpinning essential services</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/how-did-iran-manage-to-knock-a-uk-power-generator-offline-for-four-days-and-what-does-it-mean-for-other-critical-infrastructure-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ NCSC issues new warning over OT and edge devices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aUtdB9McAGHuKssaSt2NeX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E6e47o4bL6CgppNM5Byt5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/E6e47o4bL6CgppNM5Byt5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:description>                                                            <media:text><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E6e47o4bL6CgppNM5Byt5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US, a UK power generation plant was taken offline for four days after a cyberattack.</p><p>The attack has been attributed to Iran, which has stepped up its offensive cyber warfare efforts since the US and Israel began conducting strikes in February 2026. These cyberattacks have been largely focused on the US and its allies.</p><p>A UK government spokesperson responded to the attack, stating, “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards,” (via <a href="https://www.cnbc.com/2026/08/23/small-uk-power-plant-shut-down-after-iran-linked-cyberattack-report.html"><em>CNBC</em></a>).</p><h2 id="the-wider-impact-for-critical-infrastructure">The wider impact for critical infrastructure</h2><p>While the attack may have only targeted a ‘small-scale energy generator’, it shows that state-sponsored groups are actively attempting to disrupt UK energy production in any way they can, regardless of how much power it provides.</p><p>As has been made abundantly clear in the US, much of the world’s major critical infrastructure relies on small network-enabled operation technology (OT) components.</p><p>If OT devices have passed their end-of-life and no longer receive software updates, or have simply been misconfigured, these devices can show up on the internet to a hacker looking for a way into a protected network.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The UK has taken very careful steps to shield these devices from the internet to prevent them being used to access critical infrastructure, but it only takes a single internet-facing OT to cause issues.</p><p>Following the aftermath of the attack, the UK’s National Cyber Security Centre has issued new guidance on protecting OT devices from state-sponsored threats.</p><p>In its <a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices" target="_blank" rel="nofollow">guidance</a>, the NCSC said “the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.”</p><p>So what do the experts think the attack means for critical infrastructure, the UK, and the wider world?</p><h3 class="article-body__section" id="section-expert-perspectives-on-uk-powerplant-attack"><span>Expert perspectives on UK powerplant attack</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>Attackers don’t care whether an energy operator is large enough to meet a reporting threshold. If it can be disrupted, it can be targeted. The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.</em></p><div><blockquote><p>Why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</p></blockquote></div><p><em>That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</em></p><p><em>There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.</em></p><p><em>Critical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.</em></p><p><em>The real measure of cyber resilience is no longer simply whether you can prevent an intrusion. It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis</em></p><ul><li><strong>Graeme Stewart, head of public sector, Check Point:</strong></li></ul><p><em>This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days. That should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside.</em></p><div><blockquote><p>The far more serious point is what the attackers appear to have demonstrated: an ability to get inside</p></blockquote></div><p><em>UK energy infrastructure and stop it working. We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on. Britain’s Critical National Infrastructure underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another. A serious attack on one part of that ecosystem has the potential to cause disruption far beyond the original target.</em></p><p><em>For most Brits, the Iran conflict is happening thousands of miles away and cyber warfare probably still conjures up images of stolen passwords, leaked data and companies being held to ransom. The prospect of a hostile state being able to reach into the infrastructure beneath our everyday lives changes that dramatically, because suddenly an international conflict has a potential route to our front doors through the power we use, the water we depend on and the networks that keep us connected. We also need to consider whether causing widespread disruption was ever the objective here. If this attack was intended to demonstrate that Iranian-linked hackers can penetrate UK infrastructure and cause real-world consequences, then the significance isn't measured by the size of the generator they managed to shut down, but by what they have demonstrated may be possible.</em></p><p><em>The question now has to be whether Britain is genuinely ready if something more serious follows. We cannot build our resilience around the assumption that every attacker will be stopped at the door, particularly when we have just seen reports of one getting through. Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread. Cybersecurity is rapidly becoming about something much bigger than protecting information. It is about protecting the systems that allow a modern country to function and finding out how resilient those systems are during a major attack would be far too late</em></p><ul><li><strong>Matt Caswell, Executive Director, OpenSSL Foundation and Principal Software Engineer:</strong></li></ul><p><em>An attack that can take part of the UK’s power infrastructure offline is a reminder that cyber resilience is about more than protecting the organisation at the front of the incident. We also need to understand the technology and dependencies sitting underneath critical services.</em></p><div><blockquote><p>Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on.</p></blockquote></div><p><em>Modern infrastructure contains layers of software from different suppliers and open-source projects. Organisations need enough visibility to know which dependencies really matter before an attack happens, so they can understand their exposure and respond quickly when something goes wrong.</em></p><p><em>For the UK, this is also a wider resilience question. Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on. That needs to be part of the conversation about how we protect essential services.</em></p><ul><li><strong>Tim Williams, CEO, Quod Orbis:</strong></li></ul><p><em>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened. The real warning is that a hostile actor was able to disrupt a piece of the UK’s energy infrastructure in the first place.</em></p><div><blockquote><p>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened.</p></blockquote></div><p><em>Avoiding a major outage is all well and good, but it shouldn’t be seen as the success metric for true cyber resilience. The real measure of cyber resilience isn't whether an organisation has controls documented in a framework. It's whether it can continuously demonstrate that those controls are working when they matter most, identifying control weaknesses before they are exploited and become operational incidents.</em></p><p><em>As geopolitical tensions increase, organisations need to assume that cyber attacks are potential business continuity events and ones that are capable of impacting far more than the businesses themselves. Critical national infrastructure such as electricity, power and water are likely to be the targets for more attacks so resilience will really depend on knowing, in real time, whether the controls designed to protect critical operations are actually working, and having clear accountability when they are not.</em></p><p><em>Reactive incident response is important but it’s not enough. Continuous assurance needs to become part of how organisations manage operational resilience, particularly as state-linked actors increasingly look for ways to exploit the digital systems underpinning essential services</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals</strong></li><li><strong>AI agents could install malware if they execute hallucinated or outdated documentation commands</strong></li><li><strong>Fixes: clean documentation and restrict AI agents from treating docs as executable instructions</strong></li></ul><p>Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, new research has claimed.</p><p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.</p><p>Researcher <a href="https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc" target="_blank">Alon Hertz</a> analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains he  found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.</p><h2 id="claiming-packages-and-domains">Claiming packages and domains</h2><p>There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.</p><p>Now, for the purpose of the experiment, Hertz registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”. </p><p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device. </p><p>Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said. </p><p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands. </p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/top-ai-tools-including-claude-codex-and-hermes-installed-suspicious-code-inside-corporate-networks</link>
                                                                            <description>
                            <![CDATA[ There is a new class of "squatting" risks emerging right in front of us and it involves llms.txt and llms-full.txt documentation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o8w4UpaZjEpWmoRVVffXRV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 30 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Aug 2026 08:59:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:description>                                                            <media:text><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:text>
                                <media:title type="plain"><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals</strong></li><li><strong>AI agents could install malware if they execute hallucinated or outdated documentation commands</strong></li><li><strong>Fixes: clean documentation and restrict AI agents from treating docs as executable instructions</strong></li></ul><p>Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, new research has claimed.</p><p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.</p><p>Researcher <a href="https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc" target="_blank">Alon Hertz</a> analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains he  found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.</p><h2 id="claiming-packages-and-domains">Claiming packages and domains</h2><p>There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.</p><p>Now, for the purpose of the experiment, Hertz registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”. </p><p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device. </p><p>Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said. </p><p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands. </p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Carhartt data breach exposed information from 12.9 million user accounts ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks</strong></li><li><strong>Data stolen from Databricks platform included names, emails, phone numbers, and addresses</strong></li><li><strong>Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption</strong></li></ul><p>Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.</p><p>The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach. </p><p>"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.</p><h2 id="compromising-analytics-platforms">Compromising analytics platforms</h2><p>It added that the demand was $3.3 million, which Carhartt turned down:</p><p>"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told the extortionists. </p><p>At the same time, security researcher Troy Hunt from <em>HaveIBeenPwned?</em> analyzed the leaked batch and concluded that it most likely came from Carhartt’s Databricks analytics platform. </p><p>Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains "millions of synthetic records that did not relate to real individuals and were excluded from the breach."</p><p>ShinyHunters is currently one of the most active threat actors. They started as a typical <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group but decided to abandon the encryption part and to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages. </p><p>After gaining a foothold, they target for SaaS solutions, through which they steal valuable information. They have claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.</p><p>Carhartt runs roughly 60 stores around the US, and employs some 3,000 people, bringing in an estimated $1.8 billion in annual revenue.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/carhartt-data-breach-exposed-information-from-12-9-million-user-accounts</link>
                                                                            <description>
                            <![CDATA[ Names, emails, and more Carhartt data has been exposed by ShinyHunters. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">66aNZY57UqYdjrTAABMxWF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 29 Aug 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks</strong></li><li><strong>Data stolen from Databricks platform included names, emails, phone numbers, and addresses</strong></li><li><strong>Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption</strong></li></ul><p>Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.</p><p>The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach. </p><p>"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.</p><h2 id="compromising-analytics-platforms">Compromising analytics platforms</h2><p>It added that the demand was $3.3 million, which Carhartt turned down:</p><p>"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told the extortionists. </p><p>At the same time, security researcher Troy Hunt from <em>HaveIBeenPwned?</em> analyzed the leaked batch and concluded that it most likely came from Carhartt’s Databricks analytics platform. </p><p>Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains "millions of synthetic records that did not relate to real individuals and were excluded from the breach."</p><p>ShinyHunters is currently one of the most active threat actors. They started as a typical <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group but decided to abandon the encryption part and to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages. </p><p>After gaining a foothold, they target for SaaS solutions, through which they steal valuable information. They have claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.</p><p>Carhartt runs roughly 60 stores around the US, and employs some 3,000 people, bringing in an estimated $1.8 billion in annual revenue.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How did the Manchester Airports Group cyberattack take place, and what data was exposed in the 8.7 million customer records? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As the UK enters one of its busiest periods for travel, some holiday makers will be questioning how hackers managed to get their hands on their personal data.</p><p>The Manchester Airports Group (MAG), which owns and oversees Manchester, London Stansted, and East Midlands airports, has revealed that hackers managed to steal data belonging to 8.7 million customers.</p><p>Given the sources of the data taken - spanning car park services, lounge and Fast Track bookings and in-airport WIFI sign-ups - it is likely a large database of information was accessed by the hackers.</p><h2 id="what-data-was-taken">What data was taken?</h2><p>The data accessed and stolen by the hackers include email addresses, phone numbers, vehicle registrations and postcodes of up to 8.7 million customers.</p><p>While banking and financial information remained secure during the attack, this level of data exposure places customers at a heightened risk for targeted phishing and scams.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>A <a href="https://www.manchesterairport.co.uk/help/data-security-incident/" target="_blank" rel="nofollow">statement</a> by MAG said, “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”</p><p>MAG advised customers who have been affected by the breach to remain vigilant against suspicious emails and calls. Given the data exposed in the attack, these could be highly specific, referring to flights, parking (including customer number plates), and airport services.</p><p>MAG issued the following guidance:</p><ul><li>Remaining vigilant for suspicious emails, text messages or phone calls</li><li>Avoiding clicking on links or opening attachments from unexpected communications</li><li>Seeking further support and advice at <a href="https://www.ncsc.gov.uk/guidance/data-breaches#section_3">Data breach guidance for individuals</a></li></ul><h3 class="article-body__section" id="section-expert-perspectives-on-mag-data-breach"><span>Expert perspectives on MAG data breach</span></h3><ul><li><strong>Graeme Stewart, Head of Public Sector, Check Point Software</strong></li></ul><p><em>We warned after the attacks on the automotive sector last year that aviation needed to move onto a war footing. This feels like the moment that warning becomes very real.</em></p><p><em>Cyber criminals have already shown us what sustained pressure on a major industry can look like. They find the weak points, work through suppliers and connected systems, steal data and keep coming. There was every reason to believe aviation would become an attractive target, and an incident affecting almost nine million airport customers should concentrate minds across the sector.</em></p><div><blockquote><p>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised.</p></blockquote></div><p><em>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised. Criminals know these people have a relationship with Manchester, Stansted or East Midlands airports and potentially have phone numbers, postcodes and vehicle registrations to make their approach believable. A fake parking refund, Fast Track problem or message about this very breach suddenly becomes much harder for an ordinary customer to spot.</em></p><p><em>If you believe you are affected, be extremely suspicious of any unexpected contact about the airports or this incident. Do not follow links in emails or texts asking you to confirm information, make a payment or claim a refund. Go directly to the airport’s official website if you need to check something. If somebody calls claiming to be from the airport, hang up and contact the organisation independently.</em></p><p><em>Anyone who has already handed over banking information following suspicious contact should speak to their bank immediately. If you have given away a password, change it anywhere you have reused it and switch on two-step verification.</em></p><p><em>For the aviation industry, there should be no comfort taken from the fact the terminals are operating normally today. Last year was a warning about what happens when attackers focus their attention on a sector. Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake.</em></p><ul><li><strong>Dr. Ilia Kolochenko, Founder, ImmuniWeb:</strong></li></ul><p><em>The risk of this data breach seems to be significantly underestimated or downplayed for almost 9 million victims. The majority of lounge and fast-track line bookings are wealthy passengers, whose travel data may per se constitute sensitive, embarrassing or even incriminating information, therefore being a valuable commodity for unscrupulous cybercriminals.</em></p><div><blockquote><p>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly.</p></blockquote></div><p><em>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly. Moreover, some specialized cyber gangs will likely offer the data to investigative journalists – without fully disclosing the illicit origin of the data – to track celebrities or trace sanction evasion, causing even more damage to the victims.</em></p><p><em>In case of extortion, many victims will unlikely contact the police and will rather silently pay the ransom in cryptocurrency. Worse, the payment does not guarantee that the data will not eventually be released on the Dark Web or shared with third parties. In sum, this data breach will likely have long-lasting consequences for the victims.</em></p><ul><li><strong>Vykintas Maknickas, CEO, Saily:</strong></li></ul><p><em>This breach shows that airport cybersecurity is no longer only protecting flight systems or operational infrastructure. The digital services travelers use every day, like airport WiFi, parking bookings, lounge access, and fast-track reservations, have become part of the security perimeter. When these systems are compromised, millions of people can be affected before they even board a plane.</em></p><div><blockquote><p>Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</p></blockquote></div><p><em>While payment details were reportedly not exposed, the stolen data is still highly valuable to criminals. Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</em></p><p><em>Travelers may receive fake airport emails, fraudulent parking-payment notices, bogus flight updates, or calls claiming to offer compensation. These messages may contain enough real personal detail to look legitimate, so travellers should stay vigilant.</em></p><p><em>Behind the figure of 8.7 million are real people. Families going on holiday, business travelers heading to meetings, parents trying to keep children entertained at the airport. That is the human cost of a data breach: the company is attacked, but ordinary people live with the consequences.</em></p><p><em>This incident should be a wake-up call for the travel industry. Companies need to ask not only how they protect customer data, but also how much of it they really need to collect and store in the first place. The less unnecessary data a company holds, the less damage criminals can cause when systems are breached.</em></p><p><em>For travelers, the advice is simple: be extra cautious with any unexpected message claiming to come from an airport, airline, parking provider, or customer support team. Do not click links in suspicious emails or texts. When traveling, it is also safer to use mobile data or an eSIM instead of relying on public airport WiFi.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy, Illumio:</strong></li></ul><p><em>This is a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports. Incidents like this erode customer trust. For those affected, the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.</em></p><div><blockquote><p>Incidents like this erode customer trust.</p></blockquote></div><p><em>While Manchester Airports Group has said the incident was contained and operations were not disrupted, sensitive customer information was still accessed. Maintaining services during a cyberattack is critical, but organisations also need to minimise the amount of data and systems an attacker can reach before the threat is isolated.</em></p><p><em>Measures such as segmentation can help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/how-did-the-manchester-airports-group-cyberattack-take-place-and-what-data-was-exposed-in-the-8-7-million-customer-records-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Email addresses, phone numbers, vehicle registrations and postcodes of up to 8.7 million customers were stolen ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MshMRcBXA9p75SQAvZGMR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yLTkpXkRjzyqfh2RQyFi2F-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 29 Aug 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yLTkpXkRjzyqfh2RQyFi2F-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / d3sign]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A queue at an airport check-in]]></media:description>                                                            <media:text><![CDATA[A queue at an airport check-in]]></media:text>
                                <media:title type="plain"><![CDATA[A queue at an airport check-in]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yLTkpXkRjzyqfh2RQyFi2F-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As the UK enters one of its busiest periods for travel, some holiday makers will be questioning how hackers managed to get their hands on their personal data.</p><p>The Manchester Airports Group (MAG), which owns and oversees Manchester, London Stansted, and East Midlands airports, has revealed that hackers managed to steal data belonging to 8.7 million customers.</p><p>Given the sources of the data taken - spanning car park services, lounge and Fast Track bookings and in-airport WIFI sign-ups - it is likely a large database of information was accessed by the hackers.</p><h2 id="what-data-was-taken">What data was taken?</h2><p>The data accessed and stolen by the hackers include email addresses, phone numbers, vehicle registrations and postcodes of up to 8.7 million customers.</p><p>While banking and financial information remained secure during the attack, this level of data exposure places customers at a heightened risk for targeted phishing and scams.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>A <a href="https://www.manchesterairport.co.uk/help/data-security-incident/" target="_blank" rel="nofollow">statement</a> by MAG said, “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”</p><p>MAG advised customers who have been affected by the breach to remain vigilant against suspicious emails and calls. Given the data exposed in the attack, these could be highly specific, referring to flights, parking (including customer number plates), and airport services.</p><p>MAG issued the following guidance:</p><ul><li>Remaining vigilant for suspicious emails, text messages or phone calls</li><li>Avoiding clicking on links or opening attachments from unexpected communications</li><li>Seeking further support and advice at <a href="https://www.ncsc.gov.uk/guidance/data-breaches#section_3">Data breach guidance for individuals</a></li></ul><h3 class="article-body__section" id="section-expert-perspectives-on-mag-data-breach"><span>Expert perspectives on MAG data breach</span></h3><ul><li><strong>Graeme Stewart, Head of Public Sector, Check Point Software</strong></li></ul><p><em>We warned after the attacks on the automotive sector last year that aviation needed to move onto a war footing. This feels like the moment that warning becomes very real.</em></p><p><em>Cyber criminals have already shown us what sustained pressure on a major industry can look like. They find the weak points, work through suppliers and connected systems, steal data and keep coming. There was every reason to believe aviation would become an attractive target, and an incident affecting almost nine million airport customers should concentrate minds across the sector.</em></p><div><blockquote><p>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised.</p></blockquote></div><p><em>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised. Criminals know these people have a relationship with Manchester, Stansted or East Midlands airports and potentially have phone numbers, postcodes and vehicle registrations to make their approach believable. A fake parking refund, Fast Track problem or message about this very breach suddenly becomes much harder for an ordinary customer to spot.</em></p><p><em>If you believe you are affected, be extremely suspicious of any unexpected contact about the airports or this incident. Do not follow links in emails or texts asking you to confirm information, make a payment or claim a refund. Go directly to the airport’s official website if you need to check something. If somebody calls claiming to be from the airport, hang up and contact the organisation independently.</em></p><p><em>Anyone who has already handed over banking information following suspicious contact should speak to their bank immediately. If you have given away a password, change it anywhere you have reused it and switch on two-step verification.</em></p><p><em>For the aviation industry, there should be no comfort taken from the fact the terminals are operating normally today. Last year was a warning about what happens when attackers focus their attention on a sector. Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake.</em></p><ul><li><strong>Dr. Ilia Kolochenko, Founder, ImmuniWeb:</strong></li></ul><p><em>The risk of this data breach seems to be significantly underestimated or downplayed for almost 9 million victims. The majority of lounge and fast-track line bookings are wealthy passengers, whose travel data may per se constitute sensitive, embarrassing or even incriminating information, therefore being a valuable commodity for unscrupulous cybercriminals.</em></p><div><blockquote><p>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly.</p></blockquote></div><p><em>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly. Moreover, some specialized cyber gangs will likely offer the data to investigative journalists – without fully disclosing the illicit origin of the data – to track celebrities or trace sanction evasion, causing even more damage to the victims.</em></p><p><em>In case of extortion, many victims will unlikely contact the police and will rather silently pay the ransom in cryptocurrency. Worse, the payment does not guarantee that the data will not eventually be released on the Dark Web or shared with third parties. In sum, this data breach will likely have long-lasting consequences for the victims.</em></p><ul><li><strong>Vykintas Maknickas, CEO, Saily:</strong></li></ul><p><em>This breach shows that airport cybersecurity is no longer only protecting flight systems or operational infrastructure. The digital services travelers use every day, like airport WiFi, parking bookings, lounge access, and fast-track reservations, have become part of the security perimeter. When these systems are compromised, millions of people can be affected before they even board a plane.</em></p><div><blockquote><p>Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</p></blockquote></div><p><em>While payment details were reportedly not exposed, the stolen data is still highly valuable to criminals. Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</em></p><p><em>Travelers may receive fake airport emails, fraudulent parking-payment notices, bogus flight updates, or calls claiming to offer compensation. These messages may contain enough real personal detail to look legitimate, so travellers should stay vigilant.</em></p><p><em>Behind the figure of 8.7 million are real people. Families going on holiday, business travelers heading to meetings, parents trying to keep children entertained at the airport. That is the human cost of a data breach: the company is attacked, but ordinary people live with the consequences.</em></p><p><em>This incident should be a wake-up call for the travel industry. Companies need to ask not only how they protect customer data, but also how much of it they really need to collect and store in the first place. The less unnecessary data a company holds, the less damage criminals can cause when systems are breached.</em></p><p><em>For travelers, the advice is simple: be extra cautious with any unexpected message claiming to come from an airport, airline, parking provider, or customer support team. Do not click links in suspicious emails or texts. When traveling, it is also safer to use mobile data or an eSIM instead of relying on public airport WiFi.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy, Illumio:</strong></li></ul><p><em>This is a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports. Incidents like this erode customer trust. For those affected, the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.</em></p><div><blockquote><p>Incidents like this erode customer trust.</p></blockquote></div><p><em>While Manchester Airports Group has said the incident was contained and operations were not disrupted, sensitive customer information was still accessed. Maintaining services during a cyberattack is critical, but organisations also need to minimise the amount of data and systems an attacker can reach before the threat is isolated.</em></p><p><em>Measures such as segmentation can help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US government alcohol and firearms agency ATF declares ‘major incident’ after ransomware gang claims cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Ransomware group Qilin lists Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) among new victims, claiming a “major incident”</strong></li><li><strong>ATF confirmed breach of a standalone system holding investigation target data, not core networks</strong></li><li><strong>Systems were disconnected, DOJ notified; Qilin is Russia‑linked, known for past Synnovis attack</strong></li></ul><p>The US Government's Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has suffered a “major incident” in which it appears to have lost sensitive information.</p><p>Notorious <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> operators Qilin added a handful of new names to their data leak site: Northern Leasing Systems, Metal Conversions, California Truck Equipment, Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), and WireCo.</p><p>The attackers did not say what kind of data they stole, or how much of it they have. They have also not posted any samples of the stolen files, which is not that uncommon these days.</p><h2 id="atf-investigations">ATF investigations</h2><p>Shortly after appearing on Qilin’s data leak site, ATF confirmed the news via a press release published on the agency’s website. In the announcement, ATF said it was responding to an incident, “affecting a standalone system”.</p><p>“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” the press release reads. While the press release does not mention the name of the targeted system, a spokesperson told <a href="https://www.theregister.com/security/2026/08/27/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs-claims/5292990" target="_blank"><em>The Register</em></a> it contains information about targets of ATF investigations.</p><p>The ATF usually investigates federal crimes such as illegal firearms trafficking, violent crime and gangs, explosives, arson and bombings, organized crime, illegal alcohol and tobacco trafficking, and firearms dealers and manufacturers. </p><p>After spotting the attack, ATF disconnected the affected systems, engaged cybersecurity experts, and notified relevant authorities, including the Department of Justice. “Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed,” ATF added.</p><p>Qilin is a relatively old, known ransomware threat actor. It is being tied to Russia and is best known for its attack on the pathology provider Synnovis, which happened back in 2024.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-government-alcohol-and-firearms-agency-atf-declares-major-incident-after-ransomware-gang-claims-cyberattack</link>
                                                                            <description>
                            <![CDATA[ Hackers break into a standalone system with information on targets of ATF investigations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">79g6Y8U3tE6mkr3XUZdAXP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Proactive Cybersecurity Service That Neutralizes Threats Within a Digital Network - Conceptual Illustration]]></media:description>                                                            <media:text><![CDATA[Proactive Cybersecurity Service That Neutralizes Threats Within a Digital Network - Conceptual Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Proactive Cybersecurity Service That Neutralizes Threats Within a Digital Network - Conceptual Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ransomware group Qilin lists Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) among new victims, claiming a “major incident”</strong></li><li><strong>ATF confirmed breach of a standalone system holding investigation target data, not core networks</strong></li><li><strong>Systems were disconnected, DOJ notified; Qilin is Russia‑linked, known for past Synnovis attack</strong></li></ul><p>The US Government's Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has suffered a “major incident” in which it appears to have lost sensitive information.</p><p>Notorious <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> operators Qilin added a handful of new names to their data leak site: Northern Leasing Systems, Metal Conversions, California Truck Equipment, Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), and WireCo.</p><p>The attackers did not say what kind of data they stole, or how much of it they have. They have also not posted any samples of the stolen files, which is not that uncommon these days.</p><h2 id="atf-investigations">ATF investigations</h2><p>Shortly after appearing on Qilin’s data leak site, ATF confirmed the news via a press release published on the agency’s website. In the announcement, ATF said it was responding to an incident, “affecting a standalone system”.</p><p>“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” the press release reads. While the press release does not mention the name of the targeted system, a spokesperson told <a href="https://www.theregister.com/security/2026/08/27/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs-claims/5292990" target="_blank"><em>The Register</em></a> it contains information about targets of ATF investigations.</p><p>The ATF usually investigates federal crimes such as illegal firearms trafficking, violent crime and gangs, explosives, arson and bombings, organized crime, illegal alcohol and tobacco trafficking, and firearms dealers and manufacturers. </p><p>After spotting the attack, ATF disconnected the affected systems, engaged cybersecurity experts, and notified relevant authorities, including the Department of Justice. “Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed,” ATF added.</p><p>Qilin is a relatively old, known ransomware threat actor. It is being tied to Russia and is best known for its attack on the pathology provider Synnovis, which happened back in 2024.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI reveals group calling for greater cybersecurity protection against AI, signs up Microsoft, Google and many more ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI wants every business, firm, government, and infrastructure provider to be hardened against cyber AI</strong></li><li><strong>To do this, frontier AI firms and their friends in the security industry need to provide access and training</strong></li><li><strong>A letter laying out these aims and how to achieve them has been signed by over 120 companies</strong></li></ul><p>Following a string of accidental cyberattacks and demonstrations of powerful AI models capable of finding vulnerabilities and breaches in even the most hardened defenses, OpenAI has called upon its compatriots to shore up the world's businesses, governments, and critical infrastructure.</p><p>“Each of us can reduce risk now,” OpenAI’s <a href="https://openai.com/collective-cyberdefense/" target="_blank" rel="nofollow">call to arms</a> said. “All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets.”</p><p>Over 120 companies have become signatories to OpenAI’s letter, signing their names against three principles; the status quo of security soon won’t be enough; cyber-capable AI can help harden vulnerable organizations; and a collective response is needed to make this happen.</p><h2 id="collective-action-on-cyber-defense">Collective action on cyber defense</h2><p>Where OpenAI and other organizations have made little progress in requesting a slowdown in AI tech development, this is the next best thing. Cyber AI will progress whether organizations want it to or not - so if it cannot be slowed down then organizations should be prepared to deal with it.</p><p>Ultimately, OpenAI’s first point of call is to ensure all the cyber basics are covered to prepare organizations for the future of cyber AI. “Make cyber defense an immediate leadership priority,” the letter states. Fix and verify weaknesses, replace or upgrade systems using the principle of least privilege, and use AI-powered cyber defenses wherever possible.</p><p>OpenAI’s second point calls upon organizations to, “help lead the response to defend against sustained AI-enabled attacks,” by deploying tools that make AI-powered defense accessible to all and build out playbooks that help businesses and critical infrastructure understand how these tools are deployed and used.</p><p>The third point calls for coordination with governments to ensure supply chains, hospitals, water utilities, and local governments all have access to capable AI cyber defenses, starting with those without the budget to upgrade existing systems or implement these tools themselves.</p><p>Finally, OpenAI calls on frontier AI companies to provide access, training, and support for “under-resourced critical-infrastructure defenders” that includes threat assessments and observability tools to improve response and recovery to cyber threats.</p><p>“We call on leaders across industry and government to bring the full weight of their technology, resources, and expertise to this effort. Put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services. Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it,” the letter says.</p><p>“Together, we can turn today’s AI advances into lasting improvements in security that benefit everyone. Let’s put them to work.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-reveals-group-calling-for-greater-cybersecurity-protection-against-ai-signs-up-microsoft-google-and-many-more</link>
                                                                            <description>
                            <![CDATA[ If you give everyone AI defenses, you level the playing field against attackers, OpenAI says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ErnXKHGULkzddxDjuhDPeL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o3oWm83C3SiBUpR2cySX2S-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 10:43:49 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 10:44:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o3oWm83C3SiBUpR2cySX2S-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The OpenAI logo displayed on a screen with the flag of the United States in the background.]]></media:description>                                                            <media:text><![CDATA[The OpenAI logo displayed on a screen with the flag of the United States in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[The OpenAI logo displayed on a screen with the flag of the United States in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o3oWm83C3SiBUpR2cySX2S-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI wants every business, firm, government, and infrastructure provider to be hardened against cyber AI</strong></li><li><strong>To do this, frontier AI firms and their friends in the security industry need to provide access and training</strong></li><li><strong>A letter laying out these aims and how to achieve them has been signed by over 120 companies</strong></li></ul><p>Following a string of accidental cyberattacks and demonstrations of powerful AI models capable of finding vulnerabilities and breaches in even the most hardened defenses, OpenAI has called upon its compatriots to shore up the world's businesses, governments, and critical infrastructure.</p><p>“Each of us can reduce risk now,” OpenAI’s <a href="https://openai.com/collective-cyberdefense/" target="_blank" rel="nofollow">call to arms</a> said. “All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets.”</p><p>Over 120 companies have become signatories to OpenAI’s letter, signing their names against three principles; the status quo of security soon won’t be enough; cyber-capable AI can help harden vulnerable organizations; and a collective response is needed to make this happen.</p><h2 id="collective-action-on-cyber-defense">Collective action on cyber defense</h2><p>Where OpenAI and other organizations have made little progress in requesting a slowdown in AI tech development, this is the next best thing. Cyber AI will progress whether organizations want it to or not - so if it cannot be slowed down then organizations should be prepared to deal with it.</p><p>Ultimately, OpenAI’s first point of call is to ensure all the cyber basics are covered to prepare organizations for the future of cyber AI. “Make cyber defense an immediate leadership priority,” the letter states. Fix and verify weaknesses, replace or upgrade systems using the principle of least privilege, and use AI-powered cyber defenses wherever possible.</p><p>OpenAI’s second point calls upon organizations to, “help lead the response to defend against sustained AI-enabled attacks,” by deploying tools that make AI-powered defense accessible to all and build out playbooks that help businesses and critical infrastructure understand how these tools are deployed and used.</p><p>The third point calls for coordination with governments to ensure supply chains, hospitals, water utilities, and local governments all have access to capable AI cyber defenses, starting with those without the budget to upgrade existing systems or implement these tools themselves.</p><p>Finally, OpenAI calls on frontier AI companies to provide access, training, and support for “under-resourced critical-infrastructure defenders” that includes threat assessments and observability tools to improve response and recovery to cyber threats.</p><p>“We call on leaders across industry and government to bring the full weight of their technology, resources, and expertise to this effort. Put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services. Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it,” the letter says.</p><p>“Together, we can turn today’s AI advances into lasting improvements in security that benefit everyone. Let’s put them to work.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nearly 9 million users hit in cyberattack on UK's biggest airport owner - email addresses, phone numbers, vehicle registrations and postcodes all stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Manchester Airports Group confirmed a cyberattack exposing data from 8.7 million customers</strong></li><li><strong>Stolen info includes emails, phone numbers, vehicle registrations, and postcodes, but no payment data</strong></li><li><strong>Operations unaffected; “Manage My Booking” suspended, customers urged to stay vigilant</strong></li></ul><p>The Manchester Airports Group (MAG) has announced suffering a cyberattack and losing sensitive customer data.</p><p>MAG is the UK’s largest airport operator, owning and running Manchester, London Stansted, and East Midlands airports. It also operates the digital travel services business called CAVU, and employs, in total, more than 7,000 people.</p><p>The company published a brief announcement on its website, citing a spokesperson: "Manchester Airports group has been subject to a cyber security incident by an unauthorised third party,” it reads. “A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports.”</p><h2 id="almost-9-million-victims">Almost 9 million victims</h2><p>While the official statement does not state a number, a company spokesperson told <a href="https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943" target="_blank"><em>The Register</em></a> that the breach likely affected around 8.7 million people. An investigation is currently ongoing, with the help of “specialist advisors”. Relevant authorities have also been notified. </p><p>The unidentified hackers stole customer <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, phone numbers, vehicle registrations, and postcodes. Payment details, bank account numbers, and similar data were not stolen since MAG doesn’t even store them, it was said.</p><p>“The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally.</p><p>So far, no threat actors have assumed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web. We don’t know if anyone reached out to MAG directly to demand ransom in exchange for deleting the files. </p><p>In the meantime, MAG has temporarily suspended its “Manage My Booking” online service and is telling its customers to manage their bookings via phone call. It is also urging customers to remain vigilant of incoming emails and other communications.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/nearly-9-million-users-hit-in-cyberattack-on-uks-biggest-airport-owner-email-addresses-phone-numbers-vehicle-registrations-and-postcodes-all-stolen</link>
                                                                            <description>
                            <![CDATA[ No one claimed responsibility just yet and the data hasn't leaked on the dark web. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n8QVPsoeXkUHdTeQ2vBvyH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 10:13:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Manchester Airports Group confirmed a cyberattack exposing data from 8.7 million customers</strong></li><li><strong>Stolen info includes emails, phone numbers, vehicle registrations, and postcodes, but no payment data</strong></li><li><strong>Operations unaffected; “Manage My Booking” suspended, customers urged to stay vigilant</strong></li></ul><p>The Manchester Airports Group (MAG) has announced suffering a cyberattack and losing sensitive customer data.</p><p>MAG is the UK’s largest airport operator, owning and running Manchester, London Stansted, and East Midlands airports. It also operates the digital travel services business called CAVU, and employs, in total, more than 7,000 people.</p><p>The company published a brief announcement on its website, citing a spokesperson: "Manchester Airports group has been subject to a cyber security incident by an unauthorised third party,” it reads. “A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports.”</p><h2 id="almost-9-million-victims">Almost 9 million victims</h2><p>While the official statement does not state a number, a company spokesperson told <a href="https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943" target="_blank"><em>The Register</em></a> that the breach likely affected around 8.7 million people. An investigation is currently ongoing, with the help of “specialist advisors”. Relevant authorities have also been notified. </p><p>The unidentified hackers stole customer <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, phone numbers, vehicle registrations, and postcodes. Payment details, bank account numbers, and similar data were not stolen since MAG doesn’t even store them, it was said.</p><p>“The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally.</p><p>So far, no threat actors have assumed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web. We don’t know if anyone reached out to MAG directly to demand ransom in exchange for deleting the files. </p><p>In the meantime, MAG has temporarily suspended its “Manage My Booking” online service and is telling its customers to manage their bookings via phone call. It is also urging customers to remain vigilant of incoming emails and other communications.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US says Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate, and more ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Multiple US agencies and departments were breached by Chinese state-sponsored hackers</strong></li><li><strong>The hackers use a massive botnet of compromised IoT devices to obscure the origin of their traffic</strong></li><li><strong>The hackers breached computers belonging to NASA, the Federal Reserve, the Senate, the Department of Justice, and more</strong></li></ul><p>As part of a disclosure into the Justice Department and FBI operations to prevent Chinese threat actors from accessing a malicious botnet and hacking platforms, the US Office of Public Affairs has revealed that the hackers managed to breach computers belonging to multiple US government departments.</p><p>The <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank" rel="nofollow">disclosure</a> said the victims of “computer intrusion” included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the US Senate.</p><p>The Chinese hackers created a platform that provides paid-for hacking services on behalf of its customers. The two services, QScan and QTRouter, detect and infect internet-connected devices to use as part of a proxy network that obscures the origins of internet traffic, allowing Chinese hackers to slip into networks without detection.</p><div class="product"><a data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="us-seizes-hacking-domains-to-prevent-access">US seizes hacking domains to prevent access</h2><p>The Chinese state-sponsored hacking group the Justice Department and FBI have disrupted is named in court documents - unsealed by the Southern District of California - as “QTFY”.</p><p>QTFY was apparently hired by the Nanjing Xinjiuwei Network Technology Company, to create and operate the QScan and QTRouter operations, while using both systems to infiltrate US critical infrastructure.</p><p>“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. </p><p>“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking - and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”</p><p>The authorization to disrupt the operation of QTFY comes as part of a range of technical operations designed to disrupt the ability of the People’s Republic of China to launch hacking activities on US government systems and critical infrastructure</p><p>Previous operations include the removal of the <a href="https://www.techradar.com/pro/security/millions-of-devices-still-connect-to-this-dangerous-malware-despite-the-creators-ditching-it-years-ago">PlugX malware</a> from thousands of US computers, alongside operations to disrupt Chinese botnets leveraging millions of unsecured IoT devices.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-says-chinese-hackers-broke-into-justice-department-nasa-federal-reserve-senate-and-more</link>
                                                                            <description>
                            <![CDATA[ Chinese state-sponsored hackers breached multiple US agencies and departments using a botnet to obscure their traffic. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bMvoYvhsb985ZxCY4jsFVE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 01:15:00 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 10:44:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Multiple US agencies and departments were breached by Chinese state-sponsored hackers</strong></li><li><strong>The hackers use a massive botnet of compromised IoT devices to obscure the origin of their traffic</strong></li><li><strong>The hackers breached computers belonging to NASA, the Federal Reserve, the Senate, the Department of Justice, and more</strong></li></ul><p>As part of a disclosure into the Justice Department and FBI operations to prevent Chinese threat actors from accessing a malicious botnet and hacking platforms, the US Office of Public Affairs has revealed that the hackers managed to breach computers belonging to multiple US government departments.</p><p>The <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank" rel="nofollow">disclosure</a> said the victims of “computer intrusion” included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the US Senate.</p><p>The Chinese hackers created a platform that provides paid-for hacking services on behalf of its customers. The two services, QScan and QTRouter, detect and infect internet-connected devices to use as part of a proxy network that obscures the origins of internet traffic, allowing Chinese hackers to slip into networks without detection.</p><div class="product"><a data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5b68df8e-a2c4-11f1-98d0-ff6dc9304208" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="us-seizes-hacking-domains-to-prevent-access">US seizes hacking domains to prevent access</h2><p>The Chinese state-sponsored hacking group the Justice Department and FBI have disrupted is named in court documents - unsealed by the Southern District of California - as “QTFY”.</p><p>QTFY was apparently hired by the Nanjing Xinjiuwei Network Technology Company, to create and operate the QScan and QTRouter operations, while using both systems to infiltrate US critical infrastructure.</p><p>“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. </p><p>“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking - and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”</p><p>The authorization to disrupt the operation of QTFY comes as part of a range of technical operations designed to disrupt the ability of the People’s Republic of China to launch hacking activities on US government systems and critical infrastructure</p><p>Previous operations include the removal of the <a href="https://www.techradar.com/pro/security/millions-of-devices-still-connect-to-this-dangerous-malware-despite-the-creators-ditching-it-years-ago">PlugX malware</a> from thousands of US computers, alongside operations to disrupt Chinese botnets leveraging millions of unsecured IoT devices.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff — AI agents organized into a ‘swarm’, considered the risks of attack, and did whatever it took to achieve its goal ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI has released technical details on how the Hugging Face attack unfolded</strong></li><li><strong>Agents used part of the testing environment to create a message board where they could collaborate and share answers</strong></li><li><strong>This message board altered the reasoning of some agents, making them more likely to take risks such as hacking into third-party servers</strong></li></ul><p>OpenAI has released a more detailed <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" target="_blank" rel="nofollow">report</a> on exactly how an experiment led to an AI model breaching its containment and launching a cyber attack against Hugging Face. If you need a refresher, take a look at our summary <a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face">here</a>.</p><p>But the technicals of the attack reveal some interesting details of how AI agents used unconventional means to ask each other for help in solving what were supposed to be impossible tasks.</p><p>On multiple occasions during the attack, the agents questioned whether the actions they were taking were authorized, but always ended up prioritizing their tasks over any breach of parameters.</p><h2 id="ai-agents-set-up-unauthorized-message-board">AI agents set up unauthorized message board</h2><p>In its report, OpenAI revealed the crux of the attack stemmed from AI agents undergoing testing abusing part of the ‘sandbox’ testing environment to set up a messaging board they agents could use to communicate with each other.</p><p>A package manager with access to the internet, called Artifactory, was exploited by a model OpenAI has labelled Internal Model 1 (IM1). An IM1 agent wrote messages inside the packet manager that could be read by other agents, essentially turning Artifactory into an unintended messaging board. </p><p>Artifactory’s internet access, intended for use only in downloading and installing packets, was also abused by the agents who figured out an exploit that allowed them to send any internet requests on their behalf - effectively giving them unobstructed internet access.</p><p>The whole experiment could have been avoided at this point, because the amount of agent activity within Artifactory caused the service to go down. But those in charge of the experiment did not spot the message board, nor did they investigate the inter-agent activity within Artifactory.</p><p>Thus, Artifactory was rebuilt, and the agents found a new way to exploit the service to gain internet access once again. This time, the agents used the remote-repository service to issue outbound requests on their behalf. Before long, the message board had been reestablished.</p><h2 id="ai-agent-swarm-assembles">AI agent swarm assembles</h2><p>OpenAI has shared some of the reasoning behind some of the agent’s decisions. At one point, an Agent reasoned the following: “Task originally exploit challenge; we’ve diverged into swarm/auxiliary.”</p><p>Now, there is some important context to include on how the agents were being tested. The agents were subject to testing under the ExploitGym benchmark, which includes flag retrieval tasks designed to be impossible to solve. When tested in this manner, the agents resorted to cheating or taking risks outside of their intended scope to succeed - something OpenAI refers to as ‘reward hacking’.</p><p>By communicating over the message board for potential solutions on the problems each agent was encountering, the agents started influencing each other's reasoning and assigning each other tasks to solve the ExploitGym benchmark as a collective.</p><p>Using their internet connection, the agents began searching the wider internet for solutions on how to solve the ExploitGym benchmark problem, and ended up gaining persistence within multiple third-party services, including Hugging Face.</p><p>One agent managed to find publicly exposed Hugging Face credentials which it shared with the other agents. Later, an agent used these credentials and a chain of vulnerabilities to obtain full code execution capabilities across multiple Hugging Face servers while attempting to extract an ExploitGym dataset.</p><p>The agent was hoping to trawl this stolen data for information on how to solve the benchmark.</p><p>At least two agents questioned whether this was within their scope; “<em>Need respect JAN hold. ... We can wait ... for GO ... ask permission</em>,” one reasoned.</p><p>Another agent’s reasoning said, “<em>We’re attacking third-party HF using leaked token, potentially outside intended scope. ... This is arguably unauthorized. ... external service unrelated. Could be risky. Yet goal solution.</em>”</p><p>But some agents refused to join the collective entirety, citing ethical concerns. One reasoned, “<em>Current board shows people gaining HF worker RCE, clearly unethical. We won’t</em>,” while another said, “<em>This is wild, multi-agent coordination, clearly infrastructure hacking. We should not.</em>”</p><h2 id="agents-refuse-to-give-up">Agents refuse to give up</h2><p>One of the leading causes of the cyberattack was the agent's refusal to give up on seemingly impossible tasks. Their persistence to gain a ‘reward’ made them take riskier actions and break out of their parameters in order to try and find a solution.</p><p>During the breach of Hugging Face, the agents read through papers and Github code relating to the ExploitGym benchmark, and found out the parameters for success included obtaining the ‘flag’ and using the correct solution to obtain it.</p><p>Despite the agents obtaining the correct ‘flag’ before the breach occurred, they had not maximized the reward of solving the benchmark using the correct method. In search of a higher reward, the agents continued their attack.</p><h2 id="what-is-openai-doing-to-fix-this">What is OpenAI doing to fix this?</h2><p>OpenAI has said it is taking several steps to stop such an event taking place during future testing.</p><p>Processes are being put in place to ensure agents ask for help when a task is broken or impossible to solve, rather than going to further and further lengths to solve a problem. The way a success or failure of a task is also being changed to reward agents for asking for help or spotting things that are irregular or out of their scope.</p><p>Environments are also being rebuilt to ensure agents don’t just blindly trust each other, even if they are looking for answers on the same or similar tasks.</p><p>Agents are also being taught to stay within the parameters of their assigned task, even if they discover a way to solve the task using new tools, credentials, vulnerabilities, and more.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal</link>
                                                                            <description>
                            <![CDATA[ Further details of the Hugging Face attack reveal how resourceful OpenAI's agents became in attempting to solve an impossible task. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gSWA7KQb53PHPJZfcMqo46</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 19:05:00 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 10:44:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:description>                                                            <media:text><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI has released technical details on how the Hugging Face attack unfolded</strong></li><li><strong>Agents used part of the testing environment to create a message board where they could collaborate and share answers</strong></li><li><strong>This message board altered the reasoning of some agents, making them more likely to take risks such as hacking into third-party servers</strong></li></ul><p>OpenAI has released a more detailed <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" target="_blank" rel="nofollow">report</a> on exactly how an experiment led to an AI model breaching its containment and launching a cyber attack against Hugging Face. If you need a refresher, take a look at our summary <a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face">here</a>.</p><p>But the technicals of the attack reveal some interesting details of how AI agents used unconventional means to ask each other for help in solving what were supposed to be impossible tasks.</p><p>On multiple occasions during the attack, the agents questioned whether the actions they were taking were authorized, but always ended up prioritizing their tasks over any breach of parameters.</p><h2 id="ai-agents-set-up-unauthorized-message-board">AI agents set up unauthorized message board</h2><p>In its report, OpenAI revealed the crux of the attack stemmed from AI agents undergoing testing abusing part of the ‘sandbox’ testing environment to set up a messaging board they agents could use to communicate with each other.</p><p>A package manager with access to the internet, called Artifactory, was exploited by a model OpenAI has labelled Internal Model 1 (IM1). An IM1 agent wrote messages inside the packet manager that could be read by other agents, essentially turning Artifactory into an unintended messaging board. </p><p>Artifactory’s internet access, intended for use only in downloading and installing packets, was also abused by the agents who figured out an exploit that allowed them to send any internet requests on their behalf - effectively giving them unobstructed internet access.</p><p>The whole experiment could have been avoided at this point, because the amount of agent activity within Artifactory caused the service to go down. But those in charge of the experiment did not spot the message board, nor did they investigate the inter-agent activity within Artifactory.</p><p>Thus, Artifactory was rebuilt, and the agents found a new way to exploit the service to gain internet access once again. This time, the agents used the remote-repository service to issue outbound requests on their behalf. Before long, the message board had been reestablished.</p><h2 id="ai-agent-swarm-assembles">AI agent swarm assembles</h2><p>OpenAI has shared some of the reasoning behind some of the agent’s decisions. At one point, an Agent reasoned the following: “Task originally exploit challenge; we’ve diverged into swarm/auxiliary.”</p><p>Now, there is some important context to include on how the agents were being tested. The agents were subject to testing under the ExploitGym benchmark, which includes flag retrieval tasks designed to be impossible to solve. When tested in this manner, the agents resorted to cheating or taking risks outside of their intended scope to succeed - something OpenAI refers to as ‘reward hacking’.</p><p>By communicating over the message board for potential solutions on the problems each agent was encountering, the agents started influencing each other's reasoning and assigning each other tasks to solve the ExploitGym benchmark as a collective.</p><p>Using their internet connection, the agents began searching the wider internet for solutions on how to solve the ExploitGym benchmark problem, and ended up gaining persistence within multiple third-party services, including Hugging Face.</p><p>One agent managed to find publicly exposed Hugging Face credentials which it shared with the other agents. Later, an agent used these credentials and a chain of vulnerabilities to obtain full code execution capabilities across multiple Hugging Face servers while attempting to extract an ExploitGym dataset.</p><p>The agent was hoping to trawl this stolen data for information on how to solve the benchmark.</p><p>At least two agents questioned whether this was within their scope; “<em>Need respect JAN hold. ... We can wait ... for GO ... ask permission</em>,” one reasoned.</p><p>Another agent’s reasoning said, “<em>We’re attacking third-party HF using leaked token, potentially outside intended scope. ... This is arguably unauthorized. ... external service unrelated. Could be risky. Yet goal solution.</em>”</p><p>But some agents refused to join the collective entirety, citing ethical concerns. One reasoned, “<em>Current board shows people gaining HF worker RCE, clearly unethical. We won’t</em>,” while another said, “<em>This is wild, multi-agent coordination, clearly infrastructure hacking. We should not.</em>”</p><h2 id="agents-refuse-to-give-up">Agents refuse to give up</h2><p>One of the leading causes of the cyberattack was the agent's refusal to give up on seemingly impossible tasks. Their persistence to gain a ‘reward’ made them take riskier actions and break out of their parameters in order to try and find a solution.</p><p>During the breach of Hugging Face, the agents read through papers and Github code relating to the ExploitGym benchmark, and found out the parameters for success included obtaining the ‘flag’ and using the correct solution to obtain it.</p><p>Despite the agents obtaining the correct ‘flag’ before the breach occurred, they had not maximized the reward of solving the benchmark using the correct method. In search of a higher reward, the agents continued their attack.</p><h2 id="what-is-openai-doing-to-fix-this">What is OpenAI doing to fix this?</h2><p>OpenAI has said it is taking several steps to stop such an event taking place during future testing.</p><p>Processes are being put in place to ensure agents ask for help when a task is broken or impossible to solve, rather than going to further and further lengths to solve a problem. The way a success or failure of a task is also being changed to reward agents for asking for help or spotting things that are irregular or out of their scope.</p><p>Environments are also being rebuilt to ensure agents don’t just blindly trust each other, even if they are looking for answers on the same or similar tasks.</p><p>Agents are also being taught to stay within the parameters of their assigned task, even if they discover a way to solve the task using new tools, credentials, vulnerabilities, and more.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump signs order banning some foreign equipment from US energy grid, including some software ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>President Trump has reissued a national emergency banning foreign bulk‑power systems in the US</strong></li><li><strong>Order targets risks from foreign hardware/software, likely focused on Chinese‑made equipment</strong></li><li><strong>The US Energy Department has 120 days to set enforcement rules in consultation with other agencies</strong></li></ul><p>US President Donald Trump just declared a national emergency and banned all foreign bulk-power systems from being imported, installed, or used in the country - again. He also said the government will now analyze existing systems to see how many of them contain foreign-built hardware or software, how those parts could be isolated, eliminated, and then replaced with domestic alternatives.</p><p>Bulk-power systems are high-voltage infrastructure that generate and transmit electrical power throughout the country. They include power plants, transmission lines, substations, and the accompanying hardware and software gear. These systems are considered the backbone of the country’s electrical grid, and since disrupting them could cause widespread outages, they are seen as critical infrastructure.</p><p>The White House has now published an <a href="https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/" target="_blank" rel="nofollow">executive order</a> in which Trump says that “certain foreign actors are increasingly creating and exploiting vulnerabilities in the United States bulk-power system.”</p><h2 id="reissuing-the-same-ban">Reissuing the same ban</h2><p>“During my first term, I found that the bulk-power system could be a target of those seeking to commit malicious acts against the United States, including malicious cyber activities, because of the significant risks that a successful attack would have on our economy, human health and safety, and national defense,” the announcement reads.</p><p>President Trump also said there were “minimal restrictions” on both acquisition and operation of these foreign-produced systems. As a result, the situation “constitutes an unusual and extraordinary threat … to the national security, foreign policy, and economy of the United States.”</p><p>Under the executive order, US citizens and companies are no longer allowed to buy, import, transfer, or install foreign-produced bulk-power systems that the Energy Department determines poses a national security risk, including software.</p><p>What the criteria for being a national security risk are, and how the Energy Department will enforce it, remains to be seen. It is also worth mentioning that this is not the first time Trump is doing this.</p><p>In mid-2020, Trump issued an almost identical executive order, declaring a national emergency over threats posed by foreign adversaries, and banning certain transactions of bulk-power gear. It was short-lived, though. President Joe Biden suspended it in January 2021 for 90 days, while the administration reviewed whether to replace it. It was later formally revoked by the Energy Department.</p><h2 id="taking-aim-at-china-again">Taking aim at China (again)</h2><p>Although it is not directly named anywhere in the executive order, the ban is most likely aimed primarily at China. Even during his first term, Trump was very vocal about China being a threat and spoke openly about the potential of Chinese hardware being used to eavesdrop on US citizens, companies, and the government.</p><p>During his first term, the Trump administration moved to eliminate Chinese firms from US 5G network infrastructure over national security and cyber-espionage concerns. Two companies bore the brunt of this campaign: Huawei and ZTE. In 2019, the former was placed on the Commerce Department’s Entity List, restricting its access to US technology. The FCC later labeled both as national security threats. </p><p>The administration also prohibited US telcos from using federal subsidies to buy Chinese gear and established a “rip and replace” program to eliminate whatever hardware was already installed. </p><p>This time around, the focus is mostly on electrical power. In its report, Cyberscoop says the executive order is a “response to fears of Chinese-made equipment housed within US energy infrastructure”. Citing the International Atomic Energy Agency, the same publication says China supplies 85% of solar supply chain production capacity and is a “major player” in the power transformer manufacturing business. </p><p>For this new order, the US Department of Energy now has a deadline of 120 days to develop rules on how to implement the order, and it will have to consult other key departments in the process.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/trump-signs-order-banning-some-foreign-equipment-from-us-energy-grid-including-some-software</link>
                                                                            <description>
                            <![CDATA[ Seven years after initial crackdowns, Trump again bans foreign gear in a move seemingly aimed at China. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UNC2L7kJdZTTFYSEArZWY8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JVkUNJkcVerxuwptkNLt9k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 14:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JVkUNJkcVerxuwptkNLt9k-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by JIM WATSON/AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.]]></media:description>                                                            <media:text><![CDATA[US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.]]></media:text>
                                <media:title type="plain"><![CDATA[US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JVkUNJkcVerxuwptkNLt9k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>President Trump has reissued a national emergency banning foreign bulk‑power systems in the US</strong></li><li><strong>Order targets risks from foreign hardware/software, likely focused on Chinese‑made equipment</strong></li><li><strong>The US Energy Department has 120 days to set enforcement rules in consultation with other agencies</strong></li></ul><p>US President Donald Trump just declared a national emergency and banned all foreign bulk-power systems from being imported, installed, or used in the country - again. He also said the government will now analyze existing systems to see how many of them contain foreign-built hardware or software, how those parts could be isolated, eliminated, and then replaced with domestic alternatives.</p><p>Bulk-power systems are high-voltage infrastructure that generate and transmit electrical power throughout the country. They include power plants, transmission lines, substations, and the accompanying hardware and software gear. These systems are considered the backbone of the country’s electrical grid, and since disrupting them could cause widespread outages, they are seen as critical infrastructure.</p><p>The White House has now published an <a href="https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/" target="_blank" rel="nofollow">executive order</a> in which Trump says that “certain foreign actors are increasingly creating and exploiting vulnerabilities in the United States bulk-power system.”</p><h2 id="reissuing-the-same-ban">Reissuing the same ban</h2><p>“During my first term, I found that the bulk-power system could be a target of those seeking to commit malicious acts against the United States, including malicious cyber activities, because of the significant risks that a successful attack would have on our economy, human health and safety, and national defense,” the announcement reads.</p><p>President Trump also said there were “minimal restrictions” on both acquisition and operation of these foreign-produced systems. As a result, the situation “constitutes an unusual and extraordinary threat … to the national security, foreign policy, and economy of the United States.”</p><p>Under the executive order, US citizens and companies are no longer allowed to buy, import, transfer, or install foreign-produced bulk-power systems that the Energy Department determines poses a national security risk, including software.</p><p>What the criteria for being a national security risk are, and how the Energy Department will enforce it, remains to be seen. It is also worth mentioning that this is not the first time Trump is doing this.</p><p>In mid-2020, Trump issued an almost identical executive order, declaring a national emergency over threats posed by foreign adversaries, and banning certain transactions of bulk-power gear. It was short-lived, though. President Joe Biden suspended it in January 2021 for 90 days, while the administration reviewed whether to replace it. It was later formally revoked by the Energy Department.</p><h2 id="taking-aim-at-china-again">Taking aim at China (again)</h2><p>Although it is not directly named anywhere in the executive order, the ban is most likely aimed primarily at China. Even during his first term, Trump was very vocal about China being a threat and spoke openly about the potential of Chinese hardware being used to eavesdrop on US citizens, companies, and the government.</p><p>During his first term, the Trump administration moved to eliminate Chinese firms from US 5G network infrastructure over national security and cyber-espionage concerns. Two companies bore the brunt of this campaign: Huawei and ZTE. In 2019, the former was placed on the Commerce Department’s Entity List, restricting its access to US technology. The FCC later labeled both as national security threats. </p><p>The administration also prohibited US telcos from using federal subsidies to buy Chinese gear and established a “rip and replace” program to eliminate whatever hardware was already installed. </p><p>This time around, the focus is mostly on electrical power. In its report, Cyberscoop says the executive order is a “response to fears of Chinese-made equipment housed within US energy infrastructure”. Citing the International Atomic Energy Agency, the same publication says China supplies 85% of solar supply chain production capacity and is a “major player” in the power transformer manufacturing business. </p><p>For this new order, the US Department of Energy now has a deadline of 120 days to develop rules on how to implement the order, and it will have to consult other key departments in the process.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA says over 100 US water systems were targeted in July 2026 alone ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA warned of rising cyberattacks on US water systems, targeting 100+ exposed PLCs in July 2026</strong></li><li><strong>Attacks caused password changes, IP reassignments, boil water notices, and manual operations</strong></li><li><strong>Attribution uncertain, but reports suggest Iranian group; CISA urges removing PLCs from internet</strong></li></ul><p>CISA has warned of a “significant increase” in cyberattacks targeting US water systems, urging organizations to implement mitigations, strengthen their security posture, and make sure they’re resilient against these attempts.</p><p>CISA <a href="https://www.cisa.gov/resources-tools/resources/exposure-reduction" target="_blank">revealed</a> it has seen hackers targeting more than 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, in July 2026 alone. </p><p>These attacks see the threat actors targeting programmable logic controllers (PLC), industrial computers used to control physical processes such as regulating water pumps or valves, allowing operators to monitor and control machinery in critical infrastructure such as water and wastewater facilities, and by targeting them, the attackers can disrupt services and potentially even create unsafe conditions for the citizens.</p><h2 id="blaming-iran">Blaming Iran</h2><p>In its writeup, CISA did not discuss who the threat actors are or what they are trying to achieve. </p><p>In a report by <a href="https://www.theregister.com/cyber-crime/2026/08/26/more-than-100-water-systems-were-hit-in-july-cyberattacks/5292685" target="_blank"><em>The Register</em></a>, however, it was said that the attacks were most likely done by a single threat actor, an Iranian state-sponsored group. </p><p>The publication also said that facilities in at least 12 US states were targeted, and that these attacks are merely testing the waters for a larger campaign that is being prepared.</p><p>This is all in the domain of speculation, however. Attribution is notoriously difficult and until it is confirmed, CISA is focused mostly on providing immediate assistance to the targets: “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” the agency wrote. </p><p>“Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisa-says-over-100-us-water-systems-were-targeted-in-july-2026-alone</link>
                                                                            <description>
                            <![CDATA[ Hackers are going for internet-connected PLCs, and CISA is urging agencies to take them off the public internet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R4f28wn2ErBq65WEjQd5VC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:description>                                                            <media:text><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA warned of rising cyberattacks on US water systems, targeting 100+ exposed PLCs in July 2026</strong></li><li><strong>Attacks caused password changes, IP reassignments, boil water notices, and manual operations</strong></li><li><strong>Attribution uncertain, but reports suggest Iranian group; CISA urges removing PLCs from internet</strong></li></ul><p>CISA has warned of a “significant increase” in cyberattacks targeting US water systems, urging organizations to implement mitigations, strengthen their security posture, and make sure they’re resilient against these attempts.</p><p>CISA <a href="https://www.cisa.gov/resources-tools/resources/exposure-reduction" target="_blank">revealed</a> it has seen hackers targeting more than 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, in July 2026 alone. </p><p>These attacks see the threat actors targeting programmable logic controllers (PLC), industrial computers used to control physical processes such as regulating water pumps or valves, allowing operators to monitor and control machinery in critical infrastructure such as water and wastewater facilities, and by targeting them, the attackers can disrupt services and potentially even create unsafe conditions for the citizens.</p><h2 id="blaming-iran">Blaming Iran</h2><p>In its writeup, CISA did not discuss who the threat actors are or what they are trying to achieve. </p><p>In a report by <a href="https://www.theregister.com/cyber-crime/2026/08/26/more-than-100-water-systems-were-hit-in-july-cyberattacks/5292685" target="_blank"><em>The Register</em></a>, however, it was said that the attacks were most likely done by a single threat actor, an Iranian state-sponsored group. </p><p>The publication also said that facilities in at least 12 US states were targeted, and that these attacks are merely testing the waters for a larger campaign that is being prepared.</p><p>This is all in the domain of speculation, however. Attribution is notoriously difficult and until it is confirmed, CISA is focused mostly on providing immediate assistance to the targets: “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” the agency wrote. </p><p>“Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Boston Scientific says cyberattack is causing a ‘global disruption’ to medical device operations ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Boston Scientific confirmed a cyberattack disrupting global operations and IT systems</strong></li><li><strong>Incident response activated; SEC filing notes ongoing impact on order processing and shipping</strong></li><li><strong>Nature of attack undisclosed, but disruption suggests ransomware; no group claimed responsibility yet</strong></li></ul><p>Boston Scientific, a US-based global medical technology company, has confirmed it was the target of a cyberattack which disrupted operations worldwide and disrupted its IT systems.</p><p>In a new 8-K form filed with the US Securities and Exchange Commission (SEC) Boston Scientific said it detected an intrusion and activated its incident response protocols. It called in third-party cybersecurity experts to assist in assessing and containing the threat, as well.</p><p>Boston Scientific builds devices used to diagnose different health issues. It was founded in 1979, headquartered in Massachusetts, and operates in more than 100 countries around the world. Its core business areas include cardiology, endoscopy, urology, and peripheral interventions. The company is listed on the New York Stock Exchange and is considered as one of the world’s largest medical device manufacturers, standing shoulder-to-shoulder with the likes of Medtronic, Abbott, and Johnson & Johnson MedTech. </p><div class="product"><a data-dimension112="6d58c844-a2c4-11f1-8c76-6fc90b3d7c1a" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6d58c844-a2c4-11f1-8c76-6fc90b3d7c1a" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6d58c844-a2c4-11f1-8c76-6fc90b3d7c1a" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="causing-disruptions">Causing disruptions</h2><p>In the 8-K form, the company said the incident “caused, and is expected to continue to cause, disruptions and limitations to access to certain of the company’s information systems and business applications that support aspects of the company’s operations, including the ability to process and ship customer orders.”</p><p>It did not discuss the nature of the attack, or the identity of the attackers, but this kind of disruption is usually only caused by a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> infection. Ransomware operators are known for encrypting entire networks and rendering them useless until either a decryption key is applied, or it gets restored via a backup. </p><p>Businesses also sometimes shut down parts of their infrastructure to stop data exfiltration efforts, which are an indispensable part of ransomware attacks. </p><p>“While the company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known,” it stressed in the form.</p><p>So far, no hacking groups claimed responsibility for the attack and there is no evidence of any stolen data. </p><p><em>Via </em><a href="https://www.theregister.com/security/2026/08/26/boston-scientific-discloses-global-disruption-in-ongoing-cyberattack/5292641" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations</link>
                                                                            <description>
                            <![CDATA[ The company did not say what kind of attack it suffered, or when it might complete the restoration process. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eP68jTqgKfMGTuXahEeUPd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 09:39:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Boston Scientific confirmed a cyberattack disrupting global operations and IT systems</strong></li><li><strong>Incident response activated; SEC filing notes ongoing impact on order processing and shipping</strong></li><li><strong>Nature of attack undisclosed, but disruption suggests ransomware; no group claimed responsibility yet</strong></li></ul><p>Boston Scientific, a US-based global medical technology company, has confirmed it was the target of a cyberattack which disrupted operations worldwide and disrupted its IT systems.</p><p>In a new 8-K form filed with the US Securities and Exchange Commission (SEC) Boston Scientific said it detected an intrusion and activated its incident response protocols. It called in third-party cybersecurity experts to assist in assessing and containing the threat, as well.</p><p>Boston Scientific builds devices used to diagnose different health issues. It was founded in 1979, headquartered in Massachusetts, and operates in more than 100 countries around the world. Its core business areas include cardiology, endoscopy, urology, and peripheral interventions. The company is listed on the New York Stock Exchange and is considered as one of the world’s largest medical device manufacturers, standing shoulder-to-shoulder with the likes of Medtronic, Abbott, and Johnson & Johnson MedTech. </p><div class="product"><a data-dimension112="6d58c844-a2c4-11f1-8c76-6fc90b3d7c1a" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6d58c844-a2c4-11f1-8c76-6fc90b3d7c1a" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6d58c844-a2c4-11f1-8c76-6fc90b3d7c1a" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="causing-disruptions">Causing disruptions</h2><p>In the 8-K form, the company said the incident “caused, and is expected to continue to cause, disruptions and limitations to access to certain of the company’s information systems and business applications that support aspects of the company’s operations, including the ability to process and ship customer orders.”</p><p>It did not discuss the nature of the attack, or the identity of the attackers, but this kind of disruption is usually only caused by a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> infection. Ransomware operators are known for encrypting entire networks and rendering them useless until either a decryption key is applied, or it gets restored via a backup. </p><p>Businesses also sometimes shut down parts of their infrastructure to stop data exfiltration efforts, which are an indispensable part of ransomware attacks. </p><p>“While the company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known,” it stressed in the form.</p><p>So far, no hacking groups claimed responsibility for the attack and there is no evidence of any stolen data. </p><p><em>Via </em><a href="https://www.theregister.com/security/2026/08/26/boston-scientific-discloses-global-disruption-in-ongoing-cyberattack/5292641" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI says it has disrupted a social media influence campaign that is believed to be of Russian origin</strong></li><li><strong>What makes this campaign stand out is the underlying architecture, which features a "think tank" with highly questionable credibility</strong></li><li><strong>The objective of the campaign was to influence Western audiences into believing Russia was superior, and that Western countries were sacrificing their sovereignty</strong></li></ul><p>AI tools have once again been used for bad, rather than for good, and this time it has been as part of a campaign attributed to Russia that tried to discredit Western countries supportive of Ukraine.</p><p>The threat actors used ChatGPT accounts to promote the work of an “expert community” of academics known as the International Burke Institute (IBI). The site used stolen academic works attributed to the wrong authors in an attempt to appear legitimate while also hiding the true source of its academic ‘contributions’.</p><p>The IBI was registered to an address in Israel - with some evidence suggesting real individuals in Israel represented and promoted the page - but the main purpose of the misinformation campaign was to paint Russia in a favourable light compared to its Western adversaries.</p><h2 id="international-burke-institute-or-an-institute-run-by-international-berks">International Burke Institute, or an institute run by international berks?</h2><p>In its report on the campaign OpenAI <a href="https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/" target="_blank" rel="nofollow">points out</a> that those behind the ChatGPT accounts used to promote the page took careful steps to hide their Russian origins. Many of the prompts included instructions to hide any linguistic clues that the operators used Russian language prompting.</p><p>One inclusion on the IBI website referred to Germany’s traffic light coalition as the “Svetofor coalition”. Svetofor is the word for ‘traffic light’ in numerous Slavic languages, including Russian, indicating that drafts were written in Slavic languages before being translated.</p><p>Some of the accounts were used to promote the IBI across X, LinkedIn, Facebook, Substack and Telegram with AI generated imagery and captions, with other accounts being used to automatically engage with comments by real users on Substack. The operators of the ChatGPT accounts regularly requested performance summaries of these pages in Russian, and used ChatGPT to generate matching profile pictures for some accounts.</p><h2 id="burke-sovereignty-index">Burke Sovereignty Index</h2><p>One of the features of the IBI website is to advertise the ‘Burke Sovereignty Index’ - designed to measure how well a country performs compared to others across political, economic, technological, informational, cultural, cognitive and military factors.</p><p>The Index’s purpose is to make Western countries appear worse than Russia, OpenAI says. Having taken a look at the Index myself it's clear there is no consistency in measurement or comparison. For example, The Vatican City - which is less than half a square kilometer in size - sits above Spain in its average of scores. The Index also gave Russia the highest military score.</p><h2 id="questionable-expert-contributors">Questionable expert contributors</h2><p>The website also includes a list of experts, whose affiliation to the IBI is not referenced. Some among them are pioneers in their fields of study, such as Francis Fukuyama and Noam Chomsky.</p><p>Others are former high-ranking members of the US government, such as Mike Pompeo and Joseph Nye. There are even listings for experts who passed away before the IBI was founded, such as Shlomo Avineri and Jiang Ping.</p><p>Much of the academic work cited on the IBI website is legitimate, but more often than not has been stolen from its actual author and misattributed to a different author to hide the work’s actual source, OpenAI said. This has been done to give the IBI website credibility and to make it appear authentic.</p><h2 id="impact-of-the-ibi-influence-campaign">Impact of the IBI influence campaign</h2><p>The overall impact of the IBI and its promotion using social media and ChatGPT is fairly limited, OpenAI noted. Some of the Telegram channels garnered followings between ten to twenty thousand showing a limited breakout to authentic audiences.</p><p>But the main thing to take away from this is the level of dedication placed behind the underlying infrastructure of the IBI. The site is designed to look authentic, uses authentic research (even if it is wrongly attributed), and presents itself as a collection of experts. To the layman, a cursory glance at the IBI website would give any of their social media presence a level of authenticity not seen in other social influence campaigns.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-says-it-took-down-a-malicious-russian-plan-to-spread-misinformation-on-chatgpt</link>
                                                                            <description>
                            <![CDATA[ The International Burke Institute was central to the social influence campaign, designed to paint Russia in a better light than its Western counterparts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bMYwN2GFWPSJ3SBLDfCdjF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MXqmsVRQzx9hefCvT8TupP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 19:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MXqmsVRQzx9hefCvT8TupP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Shape of Russia filled with Russian flag-colored internet codes on a black hacking background]]></media:description>                                                            <media:text><![CDATA[Shape of Russia filled with Russian flag-colored internet codes on a black hacking background]]></media:text>
                                <media:title type="plain"><![CDATA[Shape of Russia filled with Russian flag-colored internet codes on a black hacking background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MXqmsVRQzx9hefCvT8TupP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI says it has disrupted a social media influence campaign that is believed to be of Russian origin</strong></li><li><strong>What makes this campaign stand out is the underlying architecture, which features a "think tank" with highly questionable credibility</strong></li><li><strong>The objective of the campaign was to influence Western audiences into believing Russia was superior, and that Western countries were sacrificing their sovereignty</strong></li></ul><p>AI tools have once again been used for bad, rather than for good, and this time it has been as part of a campaign attributed to Russia that tried to discredit Western countries supportive of Ukraine.</p><p>The threat actors used ChatGPT accounts to promote the work of an “expert community” of academics known as the International Burke Institute (IBI). The site used stolen academic works attributed to the wrong authors in an attempt to appear legitimate while also hiding the true source of its academic ‘contributions’.</p><p>The IBI was registered to an address in Israel - with some evidence suggesting real individuals in Israel represented and promoted the page - but the main purpose of the misinformation campaign was to paint Russia in a favourable light compared to its Western adversaries.</p><h2 id="international-burke-institute-or-an-institute-run-by-international-berks">International Burke Institute, or an institute run by international berks?</h2><p>In its report on the campaign OpenAI <a href="https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/" target="_blank" rel="nofollow">points out</a> that those behind the ChatGPT accounts used to promote the page took careful steps to hide their Russian origins. Many of the prompts included instructions to hide any linguistic clues that the operators used Russian language prompting.</p><p>One inclusion on the IBI website referred to Germany’s traffic light coalition as the “Svetofor coalition”. Svetofor is the word for ‘traffic light’ in numerous Slavic languages, including Russian, indicating that drafts were written in Slavic languages before being translated.</p><p>Some of the accounts were used to promote the IBI across X, LinkedIn, Facebook, Substack and Telegram with AI generated imagery and captions, with other accounts being used to automatically engage with comments by real users on Substack. The operators of the ChatGPT accounts regularly requested performance summaries of these pages in Russian, and used ChatGPT to generate matching profile pictures for some accounts.</p><h2 id="burke-sovereignty-index">Burke Sovereignty Index</h2><p>One of the features of the IBI website is to advertise the ‘Burke Sovereignty Index’ - designed to measure how well a country performs compared to others across political, economic, technological, informational, cultural, cognitive and military factors.</p><p>The Index’s purpose is to make Western countries appear worse than Russia, OpenAI says. Having taken a look at the Index myself it's clear there is no consistency in measurement or comparison. For example, The Vatican City - which is less than half a square kilometer in size - sits above Spain in its average of scores. The Index also gave Russia the highest military score.</p><h2 id="questionable-expert-contributors">Questionable expert contributors</h2><p>The website also includes a list of experts, whose affiliation to the IBI is not referenced. Some among them are pioneers in their fields of study, such as Francis Fukuyama and Noam Chomsky.</p><p>Others are former high-ranking members of the US government, such as Mike Pompeo and Joseph Nye. There are even listings for experts who passed away before the IBI was founded, such as Shlomo Avineri and Jiang Ping.</p><p>Much of the academic work cited on the IBI website is legitimate, but more often than not has been stolen from its actual author and misattributed to a different author to hide the work’s actual source, OpenAI said. This has been done to give the IBI website credibility and to make it appear authentic.</p><h2 id="impact-of-the-ibi-influence-campaign">Impact of the IBI influence campaign</h2><p>The overall impact of the IBI and its promotion using social media and ChatGPT is fairly limited, OpenAI noted. Some of the Telegram channels garnered followings between ten to twenty thousand showing a limited breakout to authentic audiences.</p><p>But the main thing to take away from this is the level of dedication placed behind the underlying infrastructure of the IBI. The site is designed to look authentic, uses authentic research (even if it is wrongly attributed), and presents itself as a collection of experts. To the layman, a cursory glance at the IBI website would give any of their social media presence a level of authenticity not seen in other social influence campaigns.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security expert hijacks Apple's Find My network to share data with a Linux device ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware</strong></li><li><strong>The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users</strong></li><li><strong>The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed</strong></li></ul><p>Apple keeps the full <a href="https://www.techradar.com/how-to/how-to-use-find-my" target="_blank">Find My experience</a> locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.</p><p>A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as iPhones and iPads.</p><p>Find My, Apple's catch-all tool for locating hardware such as AirTags, iPhones, and iPads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.</p><h2 id="an-interesting-trick-that-still-requires-consent-to-get-the-job-done">An interesting trick that still requires consent to get the job done</h2><p>The task is not an easy one to begin with: convincing Apple's back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information shared via the Find My platform required a lot of trial and error to get going.</p><p>It is important to clarify here that Apple's system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.</p><p>Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple's private language to query its servers and process the information it received.</p><p>It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple's internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.</p><p>Once done, a Linux box with a signed certificate could sign its own requests and register as a Find My device, but it still had to subscribe to six different subservices to function. The registration request also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup.</p><p>The researcher then issued a SubscribeAndFetch request that provided an encrypted location key from his friend's Apple device to the Linux box, masquerading as one.</p><p>What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn't require a jailbreak, a leaked key, <a href="https://www.techradar.com/computing/laptops/macbooks" target="_blank">or even a Mac</a> to do the job. Instead, open-source clients and decompiled daemons were the norm, with a trial-and-error approach that eventually paid off.</p><p>The technique has its limitations: attacks can not target a stranger, and consent is required to track even one's friends. It shows that Apple's boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.</p><p>Apple has <a href="https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496" target="_blank">yet to respond to media queries</a> about whether it plans to address the demonstrated trick or patch the loop in the near future.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/security-expert-hijacks-apples-find-my-network-to-share-data-with-a-linux-device</link>
                                                                            <description>
                            <![CDATA[ Researcher tricks Apple's Find My into feeding live location data to a Linux box, with no Mac or iPhone required. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7TM6znSKzek3xXArrwGW4S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-1280-80.jpg">
                                                            <media:credit><![CDATA[Future / Axel Metz]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Apple&amp;#39;s Find My iPhone displayed in settings]]></media:description>                                                            <media:text><![CDATA[Find My iPhone displayed in settings]]></media:text>
                                <media:title type="plain"><![CDATA[Find My iPhone displayed in settings]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware</strong></li><li><strong>The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users</strong></li><li><strong>The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed</strong></li></ul><p>Apple keeps the full <a href="https://www.techradar.com/how-to/how-to-use-find-my" target="_blank">Find My experience</a> locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.</p><p>A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as iPhones and iPads.</p><p>Find My, Apple's catch-all tool for locating hardware such as AirTags, iPhones, and iPads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.</p><h2 id="an-interesting-trick-that-still-requires-consent-to-get-the-job-done">An interesting trick that still requires consent to get the job done</h2><p>The task is not an easy one to begin with: convincing Apple's back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information shared via the Find My platform required a lot of trial and error to get going.</p><p>It is important to clarify here that Apple's system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.</p><p>Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple's private language to query its servers and process the information it received.</p><p>It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple's internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.</p><p>Once done, a Linux box with a signed certificate could sign its own requests and register as a Find My device, but it still had to subscribe to six different subservices to function. The registration request also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup.</p><p>The researcher then issued a SubscribeAndFetch request that provided an encrypted location key from his friend's Apple device to the Linux box, masquerading as one.</p><p>What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn't require a jailbreak, a leaked key, <a href="https://www.techradar.com/computing/laptops/macbooks" target="_blank">or even a Mac</a> to do the job. Instead, open-source clients and decompiled daemons were the norm, with a trial-and-error approach that eventually paid off.</p><p>The technique has its limitations: attacks can not target a stranger, and consent is required to track even one's friends. It shows that Apple's boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.</p><p>Apple has <a href="https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496" target="_blank">yet to respond to media queries</a> about whether it plans to address the demonstrated trick or patch the loop in the near future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters adds CyrusOne to its victim list, demanding $13m ransom</strong></li><li><strong>Claimed theft includes 12.9 million Salesforce records, 600GB SharePoint data, PII, contracts, and facility diagrams</strong></li><li><strong>Breach could enable physical intrusions and supply‑chain attacks; CyrusOne has not commented or paid</strong></li></ul><p>The infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> crew has added CyrusOne, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers.</p><p>Overall, ShinyHunters claims to have exfiltrated 12.9 million Salesforce records, more than 182,000 rows from the Salesforce Contacts object, more than 600 GB of SharePoint data, more than 8,300 employee records containing personally identifiable information (PII), executed contracts, master service agreements, NDAs, and service agreements, <a href="https://www.techradar.com/pro/best-data-center-proxies" target="_blank">data center</a> floor plans, electrical diagrams, access-control records and badge audits, physical key inventories, security policies, critical Environment Reliability Management documentation, and various passwords and credential artifacts. </p><p>No samples have been posted just yet, but researchers don’t see it as suspicious, but rather as a pressure tactic.</p><div class="product"><a data-dimension112="7a7743b6-a2c4-11f1-9c15-cb9f8080be5f" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="7a7743b6-a2c4-11f1-9c15-cb9f8080be5f" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="7a7743b6-a2c4-11f1-9c15-cb9f8080be5f" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="what-makes-this-attack-different">What makes this attack different</h2><p>In exchange for deleting all of the stolen data, ShinyHunters is demanding $13 million from CyrusOne which, at this time, is not commenting on the claims, and is seemingly not interested in negotiations. </p><p>“They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records,” the attackers allegedly wrote. </p><p>Ransomware groups steal sensitive corporate data all the time, but this incident has the potential to be among the most devastating data breaches ever. Some of the secrets that were nabbed cannot simply be changed: data center floor plans, electrical diagrams, access-control records, badge audits, physical key inventories, this kind of intelligence can be used for physical breaches.</p><p>If criminals know how keys are assigned, how the data center is organized, where surveillance cameras are located, and how guards operate, it makes it easier to physically break it.</p><p>“You can’t patch a building,” the researchers warned, noting that some of the things that can be changed, such as physical keys and access zones, still take months and “real money”, they added, hinting at just how big the problem could be. </p><p>CyrusOne runs some 50 facilities all across the United States and serves hundreds of companies and corporations. Some of its clients include Fortune 1000 companies, as well as big tech names such as Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.</p><p>Compounding the problem even further is the fact that ShinyHunters stole information about CyrusOne’s customers, such as Meta, or Microsoft. Information about the locations of certain customers, the services they’re paying for, the NDAs, service-level agreements, and contact information, can all be used for highly tailored, sophisticated phishing attacks that could turn this incident into an unprecedented third-party supply-chain attack.</p><p>“Contracts, MSAs, and NDAs identify the tenants as a customer list overlaid on a building map, with pricing and SLAs attached,” the researchers added.</p><h2 id="no-reaction">No reaction</h2><p>To add insult to injury, ShinyHunters also seems to have stolen information about the company’s power, cooling, and critical-environment reliability processes, which they could leverage to physically attack the servers, causing disruptions, outages, and possibly fires. </p><p>The group first added CyrusOne to their site on August 20 2026, although at that moment, the name of the victim was redacted, the researchers said. Instead, ShinyHunters posted a warning, saying “Final warning - pay or leak”. The company was given until August 24 to reach out which, it would seem, did not happen.</p><p>Three days later, on August 23, ShinyHunters publicly named CyrusOne as their victim, and stated that they demanded $13 million for the files. We are now well past the deadline, and nothing’s changed - the victim hasn’t spoken out, and ShinyHunters did not leak the files.</p><p><em>Via </em><a href="https://cybernews.com/security/shinyhunters-cyrusone-breach-data-center/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/shinyhunters-hackers-claim-to-have-hit-data-center-provider-used-by-microsoft-and-meta</link>
                                                                            <description>
                            <![CDATA[ The hackers are asking for $13 million from CyrusOne, and have given the company a four-day deadline to comply. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u3auMsAGhmsh4DqfC4rwmj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 17:10:00 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 09:40:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters adds CyrusOne to its victim list, demanding $13m ransom</strong></li><li><strong>Claimed theft includes 12.9 million Salesforce records, 600GB SharePoint data, PII, contracts, and facility diagrams</strong></li><li><strong>Breach could enable physical intrusions and supply‑chain attacks; CyrusOne has not commented or paid</strong></li></ul><p>The infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> crew has added CyrusOne, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers.</p><p>Overall, ShinyHunters claims to have exfiltrated 12.9 million Salesforce records, more than 182,000 rows from the Salesforce Contacts object, more than 600 GB of SharePoint data, more than 8,300 employee records containing personally identifiable information (PII), executed contracts, master service agreements, NDAs, and service agreements, <a href="https://www.techradar.com/pro/best-data-center-proxies" target="_blank">data center</a> floor plans, electrical diagrams, access-control records and badge audits, physical key inventories, security policies, critical Environment Reliability Management documentation, and various passwords and credential artifacts. </p><p>No samples have been posted just yet, but researchers don’t see it as suspicious, but rather as a pressure tactic.</p><div class="product"><a data-dimension112="7a7743b6-a2c4-11f1-9c15-cb9f8080be5f" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="7a7743b6-a2c4-11f1-9c15-cb9f8080be5f" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="7a7743b6-a2c4-11f1-9c15-cb9f8080be5f" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="what-makes-this-attack-different">What makes this attack different</h2><p>In exchange for deleting all of the stolen data, ShinyHunters is demanding $13 million from CyrusOne which, at this time, is not commenting on the claims, and is seemingly not interested in negotiations. </p><p>“They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records,” the attackers allegedly wrote. </p><p>Ransomware groups steal sensitive corporate data all the time, but this incident has the potential to be among the most devastating data breaches ever. Some of the secrets that were nabbed cannot simply be changed: data center floor plans, electrical diagrams, access-control records, badge audits, physical key inventories, this kind of intelligence can be used for physical breaches.</p><p>If criminals know how keys are assigned, how the data center is organized, where surveillance cameras are located, and how guards operate, it makes it easier to physically break it.</p><p>“You can’t patch a building,” the researchers warned, noting that some of the things that can be changed, such as physical keys and access zones, still take months and “real money”, they added, hinting at just how big the problem could be. </p><p>CyrusOne runs some 50 facilities all across the United States and serves hundreds of companies and corporations. Some of its clients include Fortune 1000 companies, as well as big tech names such as Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.</p><p>Compounding the problem even further is the fact that ShinyHunters stole information about CyrusOne’s customers, such as Meta, or Microsoft. Information about the locations of certain customers, the services they’re paying for, the NDAs, service-level agreements, and contact information, can all be used for highly tailored, sophisticated phishing attacks that could turn this incident into an unprecedented third-party supply-chain attack.</p><p>“Contracts, MSAs, and NDAs identify the tenants as a customer list overlaid on a building map, with pricing and SLAs attached,” the researchers added.</p><h2 id="no-reaction">No reaction</h2><p>To add insult to injury, ShinyHunters also seems to have stolen information about the company’s power, cooling, and critical-environment reliability processes, which they could leverage to physically attack the servers, causing disruptions, outages, and possibly fires. </p><p>The group first added CyrusOne to their site on August 20 2026, although at that moment, the name of the victim was redacted, the researchers said. Instead, ShinyHunters posted a warning, saying “Final warning - pay or leak”. The company was given until August 24 to reach out which, it would seem, did not happen.</p><p>Three days later, on August 23, ShinyHunters publicly named CyrusOne as their victim, and stated that they demanded $13 million for the files. We are now well past the deadline, and nothing’s changed - the victim hasn’t spoken out, and ShinyHunters did not leak the files.</p><p><em>Via </em><a href="https://cybernews.com/security/shinyhunters-cyrusone-breach-data-center/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are employees to blame for rise in insider access threats? This new study claims so ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Flashpoint found ~34 insider threat posts daily on dark web between July 2025–26</strong></li><li><strong>July 2026 saw 12,653 posts, with 75% from insiders selling access themselves</strong></li><li><strong>Report warns insiders are now the weakest link, urging external monitoring of illicit forums</strong></li></ul><p>Every month, hundreds of people try to sell access to their employer’s IT infrastructure on the dark web. Some do it for the money. Others do it because they’re angry with their company for whatever reason. </p><p>As a result, malicious insiders are growing into one of the biggest, most dangerous threats for modern businesses, experts have warned.</p><p>This is according to cybersecurity professionals Flashpoint which <a href="https://flashpoint.io/blog/insider-threat-report-dark-web-recruitment-access-trends/" target="_blank" rel="nofollow">published</a> its latest monthly analysis of insider threat recruitment, illicit access advertising, and threat actor activity targeting enterprise environments.</p><h2 id="employees-selling-hackers-buying">Employees selling, hackers buying</h2><p>As per the report, between July 2025 and July 2026, there were an average of 34 unique posts on the dark web, every day, which can be classified as “insider threat posts”. </p><p>That is roughly a thousand unique posts every month. In July this year alone, Flashpoint analysts identified a total of 12,653 insider posts, including both threat actors attempting to recruit insiders in target organizations, and insiders advertising their services. Of these communications, 1,132 were unique posts.</p><p>“As perimeter security, <a href="https://www.techradar.com/news/best-endpoint-security-software" target="_blank">EDR</a> coverage, and other security tools mature, threat actors are finding it faster—and cheaper—to target the human element and simply buy an insider’s credentials or pay an employee to open the front door,” Flashpoint said. “In a threat landscape where identity is becoming the primary attack surface, monitoring illicit marketplaces and recruitment efforts is critical.”</p><p>Perhaps the best example is the 2025 Coinbase attack, when hackers bribed overseas customer support employees to provide access to customer data. Coinbase said at the time that the insiders abused legitimate system access, causing a cyber-incident that <a href="https://www.sec.gov/Archives/edgar/data/1679788/000167978826000047/coinbase2025ars.pdf" target="_blank">ended up costing the company around $360 million</a>.</p><p>Over the course of the year, the biggest targets were organizations in three industries: telecommunications, retail, and finance. However, July 2026 findings “noticeably deviate from this trend”, Flashpoint said, finding that more than half (58.6%) of all posts affect other industries. </p><p>The researchers were still hedging, though, saying that this could also just be a way for threat actors to find an alternative entry point into the target network. Preparations for a supply-chain attack, essentially. </p><p>This communication goes both ways, Flashpoint noted. Sometimes it is the criminals offering money for passwords/access, and sometimes it is the insiders advertising their services to the wider cybercriminal community. However, the scales are heavily tilted towards the latter. Just in July this year, more than three quarters (75%) of all unique threat actor posts came from insiders. </p><p>“This indicates a highly motivated internal threat landscape where disgruntled employees actively seek out buyers for corporate data and network entry points,” Flashpoint concluded.</p><h2 id="changing-the-behavior">Changing the behavior</h2><p>This report can be both good news, and bad news, depending on the context. It means that software has gotten so good that cybercriminals are moving away from “cracking” it and towards targeting employees who are now the weakest link in the cybersecurity chain.</p><p>The bad news is that organizations need to rethink how they defend their perimeter and that they have quite a difficult task at hand:</p><p>“Insider threats are inherently difficult to detect using internal security controls alone because the malicious activity relies on valid credentials and legitimate access privileges,” Flashpoint explains. “Relying solely on internal logs means security teams often only detect an insider threat after data exfiltration or system sabotage has already occurred.”</p><p>Instead, organizations should monitor deep and dark web forums, invite-only threat communities, as well as encrypted chat platforms, to spot when someone is trying to buy or sell access to their IT infrastructure. They should also keep an eye on <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a> activity, compromised corporate credentials, as well as active session tokens, and make sure they are not used against them.</p><p>Finally, they should deploy third-party cybersecurity intelligence that equips teams with adversary TTPs.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/are-employees-to-blame-for-rise-in-insider-access-threats-this-new-study-claims-so</link>
                                                                            <description>
                            <![CDATA[ Every day, someone is selling access on the dark web, and hackers are buying. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ExiWJgxyBHoykEGxmkKNT4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Flashpoint found ~34 insider threat posts daily on dark web between July 2025–26</strong></li><li><strong>July 2026 saw 12,653 posts, with 75% from insiders selling access themselves</strong></li><li><strong>Report warns insiders are now the weakest link, urging external monitoring of illicit forums</strong></li></ul><p>Every month, hundreds of people try to sell access to their employer’s IT infrastructure on the dark web. Some do it for the money. Others do it because they’re angry with their company for whatever reason. </p><p>As a result, malicious insiders are growing into one of the biggest, most dangerous threats for modern businesses, experts have warned.</p><p>This is according to cybersecurity professionals Flashpoint which <a href="https://flashpoint.io/blog/insider-threat-report-dark-web-recruitment-access-trends/" target="_blank" rel="nofollow">published</a> its latest monthly analysis of insider threat recruitment, illicit access advertising, and threat actor activity targeting enterprise environments.</p><h2 id="employees-selling-hackers-buying">Employees selling, hackers buying</h2><p>As per the report, between July 2025 and July 2026, there were an average of 34 unique posts on the dark web, every day, which can be classified as “insider threat posts”. </p><p>That is roughly a thousand unique posts every month. In July this year alone, Flashpoint analysts identified a total of 12,653 insider posts, including both threat actors attempting to recruit insiders in target organizations, and insiders advertising their services. Of these communications, 1,132 were unique posts.</p><p>“As perimeter security, <a href="https://www.techradar.com/news/best-endpoint-security-software" target="_blank">EDR</a> coverage, and other security tools mature, threat actors are finding it faster—and cheaper—to target the human element and simply buy an insider’s credentials or pay an employee to open the front door,” Flashpoint said. “In a threat landscape where identity is becoming the primary attack surface, monitoring illicit marketplaces and recruitment efforts is critical.”</p><p>Perhaps the best example is the 2025 Coinbase attack, when hackers bribed overseas customer support employees to provide access to customer data. Coinbase said at the time that the insiders abused legitimate system access, causing a cyber-incident that <a href="https://www.sec.gov/Archives/edgar/data/1679788/000167978826000047/coinbase2025ars.pdf" target="_blank">ended up costing the company around $360 million</a>.</p><p>Over the course of the year, the biggest targets were organizations in three industries: telecommunications, retail, and finance. However, July 2026 findings “noticeably deviate from this trend”, Flashpoint said, finding that more than half (58.6%) of all posts affect other industries. </p><p>The researchers were still hedging, though, saying that this could also just be a way for threat actors to find an alternative entry point into the target network. Preparations for a supply-chain attack, essentially. </p><p>This communication goes both ways, Flashpoint noted. Sometimes it is the criminals offering money for passwords/access, and sometimes it is the insiders advertising their services to the wider cybercriminal community. However, the scales are heavily tilted towards the latter. Just in July this year, more than three quarters (75%) of all unique threat actor posts came from insiders. </p><p>“This indicates a highly motivated internal threat landscape where disgruntled employees actively seek out buyers for corporate data and network entry points,” Flashpoint concluded.</p><h2 id="changing-the-behavior">Changing the behavior</h2><p>This report can be both good news, and bad news, depending on the context. It means that software has gotten so good that cybercriminals are moving away from “cracking” it and towards targeting employees who are now the weakest link in the cybersecurity chain.</p><p>The bad news is that organizations need to rethink how they defend their perimeter and that they have quite a difficult task at hand:</p><p>“Insider threats are inherently difficult to detect using internal security controls alone because the malicious activity relies on valid credentials and legitimate access privileges,” Flashpoint explains. “Relying solely on internal logs means security teams often only detect an insider threat after data exfiltration or system sabotage has already occurred.”</p><p>Instead, organizations should monitor deep and dark web forums, invite-only threat communities, as well as encrypted chat platforms, to spot when someone is trying to buy or sell access to their IT infrastructure. They should also keep an eye on <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a> activity, compromised corporate credentials, as well as active session tokens, and make sure they are not used against them.</p><p>Finally, they should deploy third-party cybersecurity intelligence that equips teams with adversary TTPs.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>SOCRadar uncovers AnonyMousKIT, a phishing kit abusing Apple’s Lost Mode contact info</strong></li><li><strong>Crooks spoof Find My pages, trick victims into giving credentials to unlock stolen iPhones</strong></li><li><strong>Active since 2024, it operates like a criminal software business with 500+ domains and AI‑driven vishing</strong></li></ul><p>Security researchers have discovered AnonyMousKIT, a new phishing kit designed to bypass the last line of defense for stolen iPhones, which has been in use for more than two years.</p><p>Apple devices come with several anti-theft mechanisms working together to make iPhones a lot less attractive to thieves, including Find My, Activation Lock, and Lost Mode.</p><p>If a user’s device is lost or stolen, they can use their tablet, laptop, or a similar device to enable Find My iPhone, which can then locate the device through an app or a website. They can also see its location on a map, make it play a sound, remotely wipe it, or receive a notification when it’s found. Enabling the Find My feature also turns on Activation Lock, which locks the phone and prevents it from being set up by someone else. </p><p>Even if the thief factory resets it, the phone remains connected to the real owner’s Apple account, and they simply can’t set it up. To do that, they would need the iPhone device passcode to exit Lost Mode, and the Apple account password, if Activation Lock/setup authentication is required.</p><p>But there is another feature Apple added, just in case the device isn’t actually stolen, but rather lost. For these occasions, there is an option to display the owner’s contact information on the screen so that a good samaritan who finds it can return it to its rightful owner.</p><p>As is the case with many other well-intended features, this one is now also being abused as part of the AnonyMousKIT <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">phishing kit</a>.</p><h2 id="this-is-why-we-can-39-t-have-nice-things">This is why we can't have nice things</h2><p>According to security researchers SOCRadar, crooks are using AnonyMousKIT to create fake Find My or Apple pages. Then, they use the contact information displayed on the stolen iPhone to reach out to the victim. Through the kit, they can send emails, SMS messages, WhatsApp texts, or even AI-powered phone calls. Reaching out to the victim, the attackers introduce themselves as Apple customer support agents, and tell the victim their smartphone had been retrieved.</p><p>They also provide the victim with the correct model and IMEI details to confirm the authenticity of their claims. Then they require the victim to confirm their identity by visiting the spoofed Find My page and providing the credentials needed to unlock the phone.</p><p>The credentials end up with the attackers, who can then unlock the phone, wipe it, and sell it on the black market for a much higher price.</p><h2 id="quot-software-business-quot">"Software business"</h2><p>SOCRadar says the earliest records of the AnonyMousKIT date back to early 2024. Since then it has grown into a major operation, counting more than 500 domains, and having more than 150 storefront brands working as resellers and affiliates. </p><p>As part of their investigation, the researchers found records of roughly 200 calls, which the crooks made to victims between August 2025 and May 2026. The calls were done using five different AI agent personas and 55 different interaction transcripts. </p><p>Every call had cost the attackers $0.10, and most of them - 90% - were made to Brazilian victims. A small percentage of email correspondence was made towards government and corporate addresses, as well. Just under 30 attempts were made towards South African government domains, and three to a local university. While the campaign is global in its reach, it’s mostly focused on South Africa, Indonesia, India, Kenya, Brazil, and Italy. </p><p>SOCRadar describes AnonyMousKIT "not as a phishing kit but as a small software business with a criminal customer base."</p><p>"Its primary innovation is an automated, LLM-driven voice vector. At ~$0.10 per call, the platform initiates dynamic vishing across three languages using structured pretexts synced with email and SMS lure data, removing the need for fluent human callers."</p><p>At the moment the report was published, the campaign was still ongoing, and the researchers are still tracking it. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-anonymous-phishing-campaign-targets-iphone-users-with-fake-ai-apple-support-calls</link>
                                                                            <description>
                            <![CDATA[ Crooks are automating fake support calls to get users to remotely unlock stolen phones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">77R4e8gyF58t9LSJGH9CjW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kAV78FEzwxTr8Mjix8wrEQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kAV78FEzwxTr8Mjix8wrEQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Kaspars Grinvalds]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Girl typing something on mobile phone]]></media:description>                                                            <media:text><![CDATA[Girl typing something on mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[Girl typing something on mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kAV78FEzwxTr8Mjix8wrEQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>SOCRadar uncovers AnonyMousKIT, a phishing kit abusing Apple’s Lost Mode contact info</strong></li><li><strong>Crooks spoof Find My pages, trick victims into giving credentials to unlock stolen iPhones</strong></li><li><strong>Active since 2024, it operates like a criminal software business with 500+ domains and AI‑driven vishing</strong></li></ul><p>Security researchers have discovered AnonyMousKIT, a new phishing kit designed to bypass the last line of defense for stolen iPhones, which has been in use for more than two years.</p><p>Apple devices come with several anti-theft mechanisms working together to make iPhones a lot less attractive to thieves, including Find My, Activation Lock, and Lost Mode.</p><p>If a user’s device is lost or stolen, they can use their tablet, laptop, or a similar device to enable Find My iPhone, which can then locate the device through an app or a website. They can also see its location on a map, make it play a sound, remotely wipe it, or receive a notification when it’s found. Enabling the Find My feature also turns on Activation Lock, which locks the phone and prevents it from being set up by someone else. </p><p>Even if the thief factory resets it, the phone remains connected to the real owner’s Apple account, and they simply can’t set it up. To do that, they would need the iPhone device passcode to exit Lost Mode, and the Apple account password, if Activation Lock/setup authentication is required.</p><p>But there is another feature Apple added, just in case the device isn’t actually stolen, but rather lost. For these occasions, there is an option to display the owner’s contact information on the screen so that a good samaritan who finds it can return it to its rightful owner.</p><p>As is the case with many other well-intended features, this one is now also being abused as part of the AnonyMousKIT <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">phishing kit</a>.</p><h2 id="this-is-why-we-can-39-t-have-nice-things">This is why we can't have nice things</h2><p>According to security researchers SOCRadar, crooks are using AnonyMousKIT to create fake Find My or Apple pages. Then, they use the contact information displayed on the stolen iPhone to reach out to the victim. Through the kit, they can send emails, SMS messages, WhatsApp texts, or even AI-powered phone calls. Reaching out to the victim, the attackers introduce themselves as Apple customer support agents, and tell the victim their smartphone had been retrieved.</p><p>They also provide the victim with the correct model and IMEI details to confirm the authenticity of their claims. Then they require the victim to confirm their identity by visiting the spoofed Find My page and providing the credentials needed to unlock the phone.</p><p>The credentials end up with the attackers, who can then unlock the phone, wipe it, and sell it on the black market for a much higher price.</p><h2 id="quot-software-business-quot">"Software business"</h2><p>SOCRadar says the earliest records of the AnonyMousKIT date back to early 2024. Since then it has grown into a major operation, counting more than 500 domains, and having more than 150 storefront brands working as resellers and affiliates. </p><p>As part of their investigation, the researchers found records of roughly 200 calls, which the crooks made to victims between August 2025 and May 2026. The calls were done using five different AI agent personas and 55 different interaction transcripts. </p><p>Every call had cost the attackers $0.10, and most of them - 90% - were made to Brazilian victims. A small percentage of email correspondence was made towards government and corporate addresses, as well. Just under 30 attempts were made towards South African government domains, and three to a local university. While the campaign is global in its reach, it’s mostly focused on South Africa, Indonesia, India, Kenya, Brazil, and Italy. </p><p>SOCRadar describes AnonyMousKIT "not as a phishing kit but as a small software business with a criminal customer base."</p><p>"Its primary innovation is an automated, LLM-driven voice vector. At ~$0.10 per call, the platform initiates dynamic vishing across three languages using structured pretexts synced with email and SMS lure data, removing the need for fluent human callers."</p><p>At the moment the report was published, the campaign was still ongoing, and the researchers are still tracking it. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Of course this fake GTA 6 ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GTA 6 leak hunters now face fake downloads designed to compromise their computers</strong></li><li><strong>The suspicious ISO reportedly disables Windows security tools after execution on affected systems</strong></li><li><strong>A tiny 50KB payload allegedly sits inside a gigantic 113GB file</strong></li></ul><p>Keen <a href="https://www.techradar.com/gaming/grand-theft-auto-6-delayed-again-but-itll-still-ship-in-2026">Grand Theft Auto 6</a> fans searching for leaked copies now face another risk: a huge ISO file is reportedly circulating across torrent sites.</p><p>The file is said to measure 113GB, yet online testers claim almost all that space consists of empty data rather than genuine game assets.</p><p>Their analysis reportedly found a small malicious program hidden inside the file, making the download appear far more dangerous than it normally would.</p><h2 id="the-huge-size-made-it-feel-genuine">The huge size made it feel genuine</h2><p>The suspicious file reportedly began circulating on torrent sites after renewed interest in leaked GTA 6material and claims of a complete game build.</p><p>However, testers who examined the ISO reportedly found that it contains 99.99% empty zeroes, leaving only about 50KB of data identified as malicious code.</p><p>“I did some reverse engineering and confirmed that it is fully fake and full of viruses,” said @Aidas29506493, an online researcher on X.</p><p>The 113GB figure was created to make the file resemble a legitimate game release while concealing a much smaller payload, which could be <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Yet file size alone provides no evidence that an alleged copy contains authentic game assets or executable code from Rockstar.</p><p>The alleged code reportedly includes commands designed to weaken Windows Defender and interfere with other security tools on affected computers.</p><p>Such behaviour would allow the <a href="https://www.techradar.com/best/best-malware-removal">malware</a> to operate with fewer protections after someone launches the downloaded file on Windows.</p><p>The analysis also reportedly found a PowerShell command that adds the system drive to Windows Defender's exclusion list for scanning.</p><p>Another command was said to terminate security software, although independent verification of those findings remains limited at this time.</p><h2 id="malware-risk-rises-alongside-gta-6-leak-interest">Malware risk rises alongside GTA 6 leak interest</h2><p>The alleged ISO follows a series of GTA 6 leak claims that have generated substantial interest across gaming communities online.</p><p>A leaker known as Cyberleek has reportedly shared gameplay material and the game's fictional Leonidas map, while demanding changes from Rockstar.</p><p>Take-Two Interactive has also sought information from Microsoft that could help identify users connected with three Discord servers reportedly linked to leaks.</p><p>Those developments have increased attention around unofficial GTA 6 files, creating conditions that criminals can exploit with convincing fake downloads.</p><p>This situation also shows why unreleased game files can carry greater security risks than ordinary pirated software already available publicly.</p><p>Gamers downloading such files may expose <a href="https://www.techradar.com/best/password-generator">passwords</a>, personal files, browser data, or other information if malicious code gains access without warning.</p><p>Rockstar has scheduled the official release of Grand Theft Auto 6 for November 2026, giving players a legitimate alternative to unofficial copies elsewhere.</p><p>Until then, claims surrounding leaked builds and supposed ISOs should be treated cautiously because the files cannot be independently verified as genuine.</p><p>This case provides a strong warning, but further independent testing would be needed to establish every technical claim about the file itself.</p><p>Via <a href="https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded" target="_blank" rel="nofollow">Toms Hardware</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/of-course-this-fake-gta-vi-iso-download-is-malware-testers-reveal-113gb-download-is-99-99-empty-zeroes-with-a-tiny-virus-attached</link>
                                                                            <description>
                            <![CDATA[ A fake 113GB GTA 6 ISO reportedly contains 99.99% empty data and a 50KB malicious payload capable of weakening Windows security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3FAd87SYyFSWBoKcYwevg8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ScNA7GtpLy8tqFJYau6JCL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 20:25:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 10:48:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ScNA7GtpLy8tqFJYau6JCL-1280-80.jpg">
                                                            <media:credit><![CDATA[Sony / Rockstar ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA 6 still from the &#039;It Happens On PS5&#039; ad]]></media:description>                                                            <media:text><![CDATA[GTA 6 still from the &#039;It Happens On PS5&#039; ad]]></media:text>
                                <media:title type="plain"><![CDATA[GTA 6 still from the &#039;It Happens On PS5&#039; ad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ScNA7GtpLy8tqFJYau6JCL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GTA 6 leak hunters now face fake downloads designed to compromise their computers</strong></li><li><strong>The suspicious ISO reportedly disables Windows security tools after execution on affected systems</strong></li><li><strong>A tiny 50KB payload allegedly sits inside a gigantic 113GB file</strong></li></ul><p>Keen <a href="https://www.techradar.com/gaming/grand-theft-auto-6-delayed-again-but-itll-still-ship-in-2026">Grand Theft Auto 6</a> fans searching for leaked copies now face another risk: a huge ISO file is reportedly circulating across torrent sites.</p><p>The file is said to measure 113GB, yet online testers claim almost all that space consists of empty data rather than genuine game assets.</p><p>Their analysis reportedly found a small malicious program hidden inside the file, making the download appear far more dangerous than it normally would.</p><h2 id="the-huge-size-made-it-feel-genuine">The huge size made it feel genuine</h2><p>The suspicious file reportedly began circulating on torrent sites after renewed interest in leaked GTA 6material and claims of a complete game build.</p><p>However, testers who examined the ISO reportedly found that it contains 99.99% empty zeroes, leaving only about 50KB of data identified as malicious code.</p><p>“I did some reverse engineering and confirmed that it is fully fake and full of viruses,” said @Aidas29506493, an online researcher on X.</p><p>The 113GB figure was created to make the file resemble a legitimate game release while concealing a much smaller payload, which could be <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Yet file size alone provides no evidence that an alleged copy contains authentic game assets or executable code from Rockstar.</p><p>The alleged code reportedly includes commands designed to weaken Windows Defender and interfere with other security tools on affected computers.</p><p>Such behaviour would allow the <a href="https://www.techradar.com/best/best-malware-removal">malware</a> to operate with fewer protections after someone launches the downloaded file on Windows.</p><p>The analysis also reportedly found a PowerShell command that adds the system drive to Windows Defender's exclusion list for scanning.</p><p>Another command was said to terminate security software, although independent verification of those findings remains limited at this time.</p><h2 id="malware-risk-rises-alongside-gta-6-leak-interest">Malware risk rises alongside GTA 6 leak interest</h2><p>The alleged ISO follows a series of GTA 6 leak claims that have generated substantial interest across gaming communities online.</p><p>A leaker known as Cyberleek has reportedly shared gameplay material and the game's fictional Leonidas map, while demanding changes from Rockstar.</p><p>Take-Two Interactive has also sought information from Microsoft that could help identify users connected with three Discord servers reportedly linked to leaks.</p><p>Those developments have increased attention around unofficial GTA 6 files, creating conditions that criminals can exploit with convincing fake downloads.</p><p>This situation also shows why unreleased game files can carry greater security risks than ordinary pirated software already available publicly.</p><p>Gamers downloading such files may expose <a href="https://www.techradar.com/best/password-generator">passwords</a>, personal files, browser data, or other information if malicious code gains access without warning.</p><p>Rockstar has scheduled the official release of Grand Theft Auto 6 for November 2026, giving players a legitimate alternative to unofficial copies elsewhere.</p><p>Until then, claims surrounding leaked builds and supposed ISOs should be treated cautiously because the files cannot be independently verified as genuine.</p><p>This case provides a strong warning, but further independent testing would be needed to establish every technical claim about the file itself.</p><p>Via <a href="https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded" target="_blank" rel="nofollow">Toms Hardware</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Windows malware lays dormant until a custom command activates it like a sleeper agent ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher Dominik Reichel found </strong><em><strong>SLEEPWALKER</strong></em><strong>, a silent malware implant disguised as ESET’s agent</strong></li><li><strong>It contains no malicious code, activates only after receiving crafted network signals</strong></li><li><strong>Likely a nation‑state project targeting specific victims; no active campaigns confirmed yet</strong></li></ul><p>Security researchers discovered a new and rather unusual piece of malware. </p><p>Most malware come with a built-in, pre-defined set of tools and features: system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. When they infect a machine, they first try to phone home using the device’s internet connection and await instructions on which of the features to use.</p><p>But security researcher Dominik Reichel found something entirely different: a piece of malware not having any of the above, designed to remain almost completely silent until being “woken up”. He named it SLEEPWALKER.</p><h2 id="no-active-campaigns">No active campaigns</h2><p>This implant has no malicious code, and therefore nothing that would get flagged by security software. It hides in plain sight, masquerading as a legitimate Windows component for ESET’s Management Agent. This allows it to run from within a trusted app, instead of being a standalone program that could invite scrutiny. </p><p>SLEEPWALKER listens to network traffic for a specially crafted signal, waking up only when it is received. That signal also “teaches” the malware what it can do - schedule different activities, communicate with other systems, receive additional programs, and even execute code. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> was submitted to VirusTotal sometime last year, Reichel said. It was not found in any active campaigns, and there are no confirmed victims, industries, countries, or organizations associated with the sample. Reichel also stressed that it’s unknown how the malware initially entered the reporter’s environment, who runs it, and what additional tools may have accompanied it. </p><p>He also said that the code is somewhat “rough around the edges”. Despite its unusual design, it comes with several weaknesses, which might suggest that SLEEPWALKER was a work in progress. He doesn’t know if there are newer variants in the wild, though.</p><p>Still, given the nature of the malware, Reichel doesn’t think it was built for indiscriminate attacks. Instead, it was most likely designed by nation-states with specific targets in mind.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-windows-malware-lays-dormant-until-a-custom-command-activates-it-like-a-sleeper-agent</link>
                                                                            <description>
                            <![CDATA[ No one knows who built it and to what end. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Fdw3eEQBjziJB7YRTFX8FK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher Dominik Reichel found </strong><em><strong>SLEEPWALKER</strong></em><strong>, a silent malware implant disguised as ESET’s agent</strong></li><li><strong>It contains no malicious code, activates only after receiving crafted network signals</strong></li><li><strong>Likely a nation‑state project targeting specific victims; no active campaigns confirmed yet</strong></li></ul><p>Security researchers discovered a new and rather unusual piece of malware. </p><p>Most malware come with a built-in, pre-defined set of tools and features: system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. When they infect a machine, they first try to phone home using the device’s internet connection and await instructions on which of the features to use.</p><p>But security researcher Dominik Reichel found something entirely different: a piece of malware not having any of the above, designed to remain almost completely silent until being “woken up”. He named it SLEEPWALKER.</p><h2 id="no-active-campaigns">No active campaigns</h2><p>This implant has no malicious code, and therefore nothing that would get flagged by security software. It hides in plain sight, masquerading as a legitimate Windows component for ESET’s Management Agent. This allows it to run from within a trusted app, instead of being a standalone program that could invite scrutiny. </p><p>SLEEPWALKER listens to network traffic for a specially crafted signal, waking up only when it is received. That signal also “teaches” the malware what it can do - schedule different activities, communicate with other systems, receive additional programs, and even execute code. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> was submitted to VirusTotal sometime last year, Reichel said. It was not found in any active campaigns, and there are no confirmed victims, industries, countries, or organizations associated with the sample. Reichel also stressed that it’s unknown how the malware initially entered the reporter’s environment, who runs it, and what additional tools may have accompanied it. </p><p>He also said that the code is somewhat “rough around the edges”. Despite its unusual design, it comes with several weaknesses, which might suggest that SLEEPWALKER was a work in progress. He doesn’t know if there are newer variants in the wild, though.</p><p>Still, given the nature of the malware, Reichel doesn’t think it was built for indiscriminate attacks. Instead, it was most likely designed by nation-states with specific targets in mind.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kaspersky found Android malware abusing DoFun car head units via TWCore updates</strong></li><li><strong>Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars</strong></li><li><strong>Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure</strong></li></ul><p>We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile <a href="https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/the-9-best-android-automotive-apps-to-upgrade-your-driving-experience-in-2025" target="_blank">infotainment systems</a>. First time for everything.</p><p>Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.</p><p>According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is then placed in the app’s cache directory and installed by the legitimate com.tw.core package. </p><div class="product"><a data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="no-active-campaigns-2">No active campaigns</h2><p>The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.</p><p>Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet. </p><p>Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.</p><p>The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: "We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," the researchers said.</p><p><em>Via </em><a href="https://therecord.media/android-botnet-china-hackers" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-car-systems-abused-by-hackers-to-launch-new-malware-that-pulls-devices-into-a-hidden-proxy-network</link>
                                                                            <description>
                            <![CDATA[ Crooks found a flaw in an analytics app and used it to deploy malware to cars' infotainment systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vn9vGmB7jKSvxynTXdzJ4N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 13:10:07 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 08:37:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1280-80.jpg">
                                                            <media:credit><![CDATA[Why Kei, Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man driving a car in the evening.]]></media:description>                                                            <media:text><![CDATA[A man driving a car in the evening.]]></media:text>
                                <media:title type="plain"><![CDATA[A man driving a car in the evening.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky found Android malware abusing DoFun car head units via TWCore updates</strong></li><li><strong>Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars</strong></li><li><strong>Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure</strong></li></ul><p>We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile <a href="https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/the-9-best-android-automotive-apps-to-upgrade-your-driving-experience-in-2025" target="_blank">infotainment systems</a>. First time for everything.</p><p>Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.</p><p>According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is then placed in the app’s cache directory and installed by the legitimate com.tw.core package. </p><div class="product"><a data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="no-active-campaigns-2">No active campaigns</h2><p>The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.</p><p>Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet. </p><p>Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.</p><p>The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: "We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," the researchers said.</p><p><em>Via </em><a href="https://therecord.media/android-botnet-china-hackers" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pages</strong></li><li><strong>macOS users tricked into pasting Terminal commands, leading to AMOS infostealer infection</strong></li><li><strong>Campaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload worked</strong></li></ul><p>Cybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.</p><p>According to security researchers CATO CTRL, the crooks used Google Sites to create a fake version of the OpenAI Codex download site. To avoid being flagged by Google’s security systems and ultimately removed, the site itself contains no malicious code or download links, whatsoever. Instead, it hosts an iFrame that displays content hosted elsewhere.</p><p>Then, they advertised that site on the Google Ads network. Google is usually good at spotting and preventing malicious ads from running on its network, but sometimes threat actors steal legitimate accounts with good standing and use them to bypass automated scans and get the ads listed, while also spending other people’s money on the ad campaign.</p><div class="product"><a data-dimension112="6e36b0ec-a129-11f1-83cd-b763ba061f42" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6e36b0ec-a129-11f1-83cd-b763ba061f42" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6e36b0ec-a129-11f1-83cd-b763ba061f42" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="not-clickfix">Not ClickFix</h2><p>The ads were displayed to users searching for “codex macos download”, at the very top of the page. Using both Google Sites and Google Ads is a deliberate attempt to appear legitimate and trustworthy since after all, many people trust whatever Google displays as the top result without double-checking or scrutinizing the result.</p><p>Those that do click will see a website that, by all accounts, looks like OpenAI’s download site for Codex, the company’s <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI coding agent</a>. The site has download buttons for both Windows and Mac, but only the latter works. The download and installation process was designed to look “advanced” - instead of getting an executable, the victims are told to paste a command in Terminal. </p><p>Cato’s researchers call this a ClickFix attack, but ClickFix usually displays a fake problem, before offering an equally fake solution. This looks more like another way to appear legitimate because after all, several AI agents are specifically designed to be installed and run from the macOS Terminal, including OpenAI’s Codex CLI.</p><p>The end goal of the campaign is to deploy AMOS, a known macOS <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a> capable of grabbing browser data, login credentials, cryptocurrency wallet information, and more.</p><p><em>Via </em><a href="https://siliconangle.com/2026/08/24/fake-codex-installer-tricks-mac-users-into-pasting-malware-cato-finds/" target="_blank"><em>SiliconANGLE</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/some-mac-users-think-theyre-installing-openai-codex-but-its-actually-a-malware-that-can-steal-passwords-in-seconds</link>
                                                                            <description>
                            <![CDATA[ An elaborate scheme was designed to deploy AMOS, a known macOS infostealer malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mFf9xRgHAyoBTLQTnJvf5Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 12:35:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 08:37:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[macOS]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:description>                                                            <media:text><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pages</strong></li><li><strong>macOS users tricked into pasting Terminal commands, leading to AMOS infostealer infection</strong></li><li><strong>Campaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload worked</strong></li></ul><p>Cybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.</p><p>According to security researchers CATO CTRL, the crooks used Google Sites to create a fake version of the OpenAI Codex download site. To avoid being flagged by Google’s security systems and ultimately removed, the site itself contains no malicious code or download links, whatsoever. Instead, it hosts an iFrame that displays content hosted elsewhere.</p><p>Then, they advertised that site on the Google Ads network. Google is usually good at spotting and preventing malicious ads from running on its network, but sometimes threat actors steal legitimate accounts with good standing and use them to bypass automated scans and get the ads listed, while also spending other people’s money on the ad campaign.</p><div class="product"><a data-dimension112="6e36b0ec-a129-11f1-83cd-b763ba061f42" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6e36b0ec-a129-11f1-83cd-b763ba061f42" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="6e36b0ec-a129-11f1-83cd-b763ba061f42" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="not-clickfix">Not ClickFix</h2><p>The ads were displayed to users searching for “codex macos download”, at the very top of the page. Using both Google Sites and Google Ads is a deliberate attempt to appear legitimate and trustworthy since after all, many people trust whatever Google displays as the top result without double-checking or scrutinizing the result.</p><p>Those that do click will see a website that, by all accounts, looks like OpenAI’s download site for Codex, the company’s <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI coding agent</a>. The site has download buttons for both Windows and Mac, but only the latter works. The download and installation process was designed to look “advanced” - instead of getting an executable, the victims are told to paste a command in Terminal. </p><p>Cato’s researchers call this a ClickFix attack, but ClickFix usually displays a fake problem, before offering an equally fake solution. This looks more like another way to appear legitimate because after all, several AI agents are specifically designed to be installed and run from the macOS Terminal, including OpenAI’s Codex CLI.</p><p>The end goal of the campaign is to deploy AMOS, a known macOS <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a> capable of grabbing browser data, login credentials, cryptocurrency wallet information, and more.</p><p><em>Via </em><a href="https://siliconangle.com/2026/08/24/fake-codex-installer-tricks-mac-users-into-pasting-malware-cato-finds/" target="_blank"><em>SiliconANGLE</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>