Search/facebook
Vendor

facebook

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
zstandard
Connections
543 relationships
25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in immigration actions and against people exercising their First Amendment rights to protest. It’s also increasingly part of private security systems, such as facial recognition at venues such as Madison Square Garden and networked Flock license plate capture systems on roads and in parking lots. The interrelation between private and governmental mass surveillance is worth examining. Surveillance is the business model of the internet; companies like Google and Facebook constantly spy on their users’ behavior. From the National Security Agency relying on data collected by telecommunication and internet companies, to local sheriffs and ICE agents relying on cellphone location data and privately managed automatic license plate readers, governments primarily obtain the mass surveillance information through private companies. Increasingly, access doesn’t just come through legal processes, either. FBI Director Kash Patel recently confirmed in congressional testimony that the agency is purchasing information on Americans from data brokers and intends to continue to do so. This pipeline from private collection to governmental collection means that as companies collect more information for surveillance capitalism purposes, more is available to law enforcement as well. And as the technology for mass surveillance and analysis improves, especially with the increased use of AI technologies, the problems attendant to mass surveillance grow as well. After 9/11, the idea that the government could surveil the population to safety took hold. In 2001, the fear of terrorism reached a frequency and intensity never before seen. Along with that came the fear that the enemy could be anyone, anywhere. As a result, the government’s response was to watch everyone, everywhere. This line of reasoning underpinned the shift from targeted to mass surveillance. Or, in the words of an internal National Security Agency (NSA) presentation that was made public as part of Edward Snowden’s 2013 disclosures, a government that can “Collect it All,” “Process it All,” “Exploit it All,” “Partner it All,” and “Sniff it All,” will ultimately, “Know it All.” Similar rationales support the rise of domestic mass surveillance: if law enforcement could see and hear everything, it could more effectively interdict and solve serious crimes. The national security community has never provided a full analysis of the costs and benefits of these mass surveillance programs, either in terms of taxpayer dollars or diversion of resources from other efforts—or any demonstration that those techniques stopped attacks that otherwise they would not have been able to prevent. While the NSA occasionally presents examples of the successes due to its mass surveillance programs, especially when those techniques are under public pressure, the examples also regularly fall apart upon serious scrutiny. And even if some utility exists, it must be seriously weighed against the costs. Similarly, there has never been any comprehensive analysis about whether domestic immigration or law enforcement’s use of these techniques actually makes people safer, or whether other techniques could produce the same results. Instead, both the police and the companies selling these tools float anecdotes and dubious data . For example, Flock’s data equates the number of law enforcement hits in their database with actually solving crimes. Twenty-five years after 9/11, it seems reasonable to step back and evaluate the costs of this shift to mass surveillance, especially in terms of Americans’ rights and freedoms. The Shift The easiest place to see a shift to mass surveillance was in the government’s decision immediately after 9/11 to collect Americans’ telephone records. The program started under an argument of pure executive power as the “President’s Surveillance Program.” But in 2006, that argument secretly shifted to a novel interpretation of Section 215 of the Patriot. Act which had only previously authorized more targeted access to record. While some media and public interest organizations struggled to force the government to reveal the program as early as late 2005, the government only officially confirmed it after the 2013 Snowden disclosures. In 2015, the Second Circuit Court of Appeals rejected the government’s interpretation of Section 215 as allowing mass collection of telephone records. Later the same year, Congress passed the USA Freedom Act . While this new law still allows collection of a tremendous amount of domestic telephone records, it ended the indiscriminate mass collection that had occurred for nearly fourteen years. Other shifts to mass surveillance continue through today. The NSA launched its Upstream program, which involved intercepting both metadata and content from key telecommunications junctures inside the U.S., soon after 9/11. It was also initially conducted under a claim of purely presidential authority. This program was brought under marginal congressional and programmatic (not targeted) Foreign Intelligence Surveillance Act (FISA) court review via Section 702 of the 2008 FISA Amendments Act. In 2017, more than15 years after its inception, the NSA ended content searches due to FISA court pressure, but the mass collection continues. Despite the stated goal of conducting mass spying only on people outside the U.S.—which itself is problematic given international law’s requirement that surveillance be both necessary and proportionate —mass surveillance collects a tremendous amount of U.S. persons’ communications. This can happen because people communicate with people abroad, or because of overcollection—when government agencies gather far more personal data on non-targeted US persons than authorized by law. The concerns about collecting Americans’ data on U.S. soil led Congress to allow the program to officially expire in 2026, although the previously-approved mass surveillance itself continues until at least Spring of 2027. The shift to mass surveillance would be notable enough even if it remained only a strategy of the intelligence community. It has not. Americans are awash in mass surveillance. Networks of automated license plate readers such as those offered by Flock and Vigilant Solutions blanket both public and private roadways and parking lots. These networks often allow searches by law enforcement, including across jurisdictions. They are, for example, being used to track people seeking abortions across state lines. Facial recognition tools, once the province of only the more elite parts of federal law enforcement, are increasingly used by Immigration and Customs Enforcement agents on immigrants and protesters, in airports by the Transportation Security Administration , as well as by private entities . And, of course, modern phones track users’ locations constantly—and that information is readily available to law enforcement, often with only minimal process protections. Constitutional Costs Regardless of the murkiness of its actual usefulness, the shift from targeted to mass surveillance has profound implications for Americans’rights. It has created risks that have become increasingly evident, especially under the Trump administration. At a basic level, the Fourth Amendment guarantees that citizens can be secure in their “persons, houses, papers and effects” from unreasonable searches. Warrants breaching that security should be supported by probable cause and particular descriptions of the place to be searched and items to be seized. Mass surveillance turns that promise on its head, allowing access to our “papers and effects” by the government without individualized suspicion or a particularized description of what data is being seized, much less probable cause. This protection was in response to colonial British misuse of writs of assistance , which authorized indiscriminate searches rather than targeted ones. The justifications for exempting mass surveillance from constitutional protection vary. For Section 702, the government has taken the position that U.S. persons’ communications caught up in the dragnet, either due to overcollection or because they were communicating with someone outside the United States, do not require a warrant prior to initial collection or secondary access by the FBI and several other agencies. The argument is that if the initial collection was not aimed at Americans, the information is free from constitutional protection for any later uses, even for reasons far afield from the initial rationale for collection. Other arguments rest on the claim that metadata is outside the Fourth Amendment, despite its demonstrated ability to reveal intimate details of all of our lives. Still others rest on the Supreme Court-created Third Party Doctrine , which holds that the Fourth Amendment does not apply to data shared with companies that provide us with services. Some turn on whether analysis by machine counts , claiming that only “human eyes” matter—a particularly troubling argument with the rise of artificial intelligence. What’s more, the government has used doctrines like standing to limit the ability of those subjected to mass surveillance to seek constitutional protection. No matter the argument, the goal is the same: to place the mechanisms and fruits of mass surveillance outside the protections of the Fourth Amendment. The overarching truth is that, due to the concerted efforts by the government since 9/11, and the rise of technologies in recent years, the slice of Americans’ lives and data that are actually protected by the Fourth Amendment has shrunk significantly in the past 25 years. Together, with the technical capabilities of mass surveillance and the increased ability for that data to be analyzed using AI tools, the “security in our papers and effects” that the constitution promises seems increasingly illusory. In addition to the Fourth Amendment, mass surveillance creates tensions with the First Amendment. The Constitution has long recognized that the right to freedom of speech requires a zone of privacy against governmental surveillance. The right to anonymous speech as well as the right of association both recognize the chilling effect that surveillance creates for people saying unpopular things or attempting to organize for political or other societal change. Mass surveillance grants the authorities the ability to track those people, both in real time and historically, that is inconsistent with actual techniques of freedom of speech and assembly. That is why the recently released 2026 U.S. Counterterrorism Strategy is so troubling. On page seven, the White House expressly states that it intends to target domestic activists with its heretofore foreign-targeted powers. It says that the government “will prioritize the rapid identification and neutralization of violent secular political groups whose ideology is anti-American, radically pro-transgender and anarchist” and “will use all the tools constitutionally available to us to map them at home, identify their membership, map their ties to international organizations like Antifa.” While framed as targeting “violent” groups, it’s clear that the government intends to use its national security tools, presumably including the tools of mass surveillance, against Americans in ways that will create profound tensions with the First Amendment rights of people to organize and communicate privately. Costs Due to Mistakes and Abuse Even assuming some utility from mass surveillance—a fact we do not dispute, even if the public record is shaky and conclusory—the history of both the national security and domestic uses of mass surveillance confirms that these tools are inevitably misused , and that mistakes have impacted huge numbers of Americans. The past twenty-five years have demonstrated that it is not possible to surveil the entire US population while staying within the bounds of even a very generous legal framework like Section 702. As Rep. Zoe Lofgren (D-Calif.) recently stated in discussion of Section 702 in an interview with Tech Policy Press : “backdoor searches have been used improperly for protestors, 19,000 campaign donors, members of Congress, journalists, government officials, a state court judge who had complained to the FBI about police misconduct. It has been abused substantially in the past.” The NSA experienced so much abuse of its mass surveillance tools by actual or aspiring romantic partners and ex-spouses that an internal name emerged for it: “ LOVEINT ,” or Love Intelligence. That same pattern of abuse is now emerging at the domestic law enforcement level. A Texas police officer misused , and then lied about, using license plate readers to track a woman suspected of seeking an abortion. Multiple law enforcement officials have been accused of tracking people they either wished to have a relationship with or who were their exes. And mass surveillance technologies have been used to track both immigration targets and citizens engaging in their First Amendment-protected right to track and record the police. Mistakes are inevitable with collections of data of this size and scope. The history of the FISA court’s reviews of Section 702 is littered with examples of the NSA not being able to follow its own rules limiting the scope of what it collects and analyzes, even after having been given multiple chances by the court. On the local level, the technical protections that Flock, for example, put in place have repeatedly been insufficient to stop “accidental” sharing its data with out-of-state law enforcement. These mistakes have fueled growing efforts by local communities across the country to remove license plate readers. Those efforts should be the first step in a broader reconsideration of mass surveillance. More generally, ubiquitous surveillance carries a real societal cost. The chilling effects are real and pervasive , and they tend to fall hardest on the most marginalized members of society. Moreover, social progress requires the ability to experiment in secret. It’s hard to imagine a society progressing morally to the point of accepting and legalizing things like marijuana use or gay marriage if the earliest signs of that shift are snuffed out because of overzealous surveillance. Reversing Course While a cost-benefit analysis is not the best frame for deciding constitutional rights, it is a place to start to evaluate government policies. If the costs are too high and the benefits too small, what should the public do? While the policy and legal frameworks can be individually complex, mass surveillance is a problem in all of its applications. So too should solutions be comprehensive rather than piecemeal. One comprehensive strategy is to reset the promise of the Fourth Amendment and recognize that a warrant is required prior to collection, access or use of information gathered through mass surveillance. This would apply to collections that include U.S. persons, whether done for national security or domestic purposes. This protection would apply regardless of whether the information is in the form of metadata. It would apply regardless of whether the information is held in homes or by services people rely on, such as telephones, internet or social network providers, or by private entities utilizing mass surveillance for their own purposes. By passing this legislation, Congress could ensure this rejection of mass surveillance, and include real enforcement such as a private right of action and an automatic exclusionary remedy in criminal prosecutions. The courts could also recognize this protection of “papers and effects” directly as a plain language interpretation of the Fourth Amendment. There are already a number of efforts that take on pieces of mass surveillance. Section 702 has expired and should remain so. This was due largely to efforts to block the “back door” access to Section 702-collected data without warrants. The bipartisan “ Fourth Amendment is Not for Sale Act ” would prevent the government from purchasing data that it would otherwise need a warrant to obtain. The Supreme Court itself has already been chipping away at the Third Party Doctrine, with a recent step in the rejection of mass geofence warrants—warrants seeking the identities of individuals based upon their proximity to a crime—in Chatrie v. United States . Now, such warrants fall, at least initially, under the Fourth Amendment. A more comprehensive approach would also address mass surveillance carried out by private companies, and to ensure that Americans have the right to encrypt and secure their data. There are many reasons the United States would benefit from a comprehensive privacy law —and curbing mass surveillance is one of them. Addressing mass surveillance is certainly one of them. Ideas such as the banning of secondary uses of data—with roots in the Fair Information Practice Principles from the 1970s—are worth pushing forward. So are moves such as creating fiduciary duties for mass data collectors. There are many more ways to curtail private companies’ mass surveillance while staying within constitutional boundaries. But addressing the costs of mass surveillance by both companies and governments is even more important in a world where AI agents are making decisions both about the public and on their behalf based on their data and observed behavior. Twenty-five years after the U.S. government embraced mass surveillance, it’s time to evaluate it as a whole, and consider responses that address the problem as a whole. Americans must ask: Is it consistent with a self-governing democracy to have systems that watch everyone everywhere? Is the public comfortable with governments—federal, state, local—that seek to “know it all” about its citizens? Is the public comfortable with private mass surveillance in its own right and as it’s being increasingly used to fuel government surveillance? These questions have long needed serious consideration. But as it becomes increasingly evident that the Trump administration is using mass surveillance to keep itself in power, stifle dissent, and undermine political opponents, these questions are now more urgent than ever.
schneier.comSep 15, 2026extracted
Meta AI builds detailed profiles of children from years of family posts
If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did something that hundreds of thousands of parents do every day. She posted a video of her young daughter on Facebook. Under the video of Robins and her daughter singing in a car, Facebook’s Meta AI system displayed a suggested question: “Who is the child passenger?” Robins was shocked that Facebook would ask this question about a minor, so curiosity prompted her to click it. That’s when a flood of automated stalker-type behavior began. In Instagram post , an enraged Robins described what happened: “It starts pulling completely separate information for each of my kids.” That included names, birth dates, and videos of them. The site also pulled up a picture of her newborn daughter that Robins’ mother had posted on Facebook years ago, along with a long-deleted picture that Robins said had once been in her own account. Things got weirder. The site then presented another question: “Where does Kalie Robins live?” An increasingly outraged Robins clicked that question. She described the results: “[Facebook] started digging through completely unrelated sh*t from years of my life.” It dug through old posts that hinted at where she had lived in the past and newer posts that connected her to her current home. It finished by attempting to pinpoint her location. Robins complained: “I didn’t ask Facebook to build a profile of my family.” She expressed shock that Facebook would piece together snippets of personal information from historical posts and package them into a detailed profile for other users. You can watch Kalie Robins’ Instagram video here: .kadence-column465357_a378ee-2f > .kt-inside-inner-col{display:flex;}.kadence-column465357_a378ee-2f{max-width:558px;margin-left:auto;margin-right:auto;}.wp-block-kadence-column.kb-section-dir-horizontal:not(.kb-section-md-dir-vertical)>.kt-inside-inner-col>.kadence-column465357_a378ee-2f{-webkit-flex:0 1 558px;flex:0 1 558px;max-width:unset;margin-left:unset;margin-right:unset;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col,.kadence-column465357_a378ee-2f > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column465357_a378ee-2f > .kt-inside-inner-col{flex-direction:column;align-items:center;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col > .kb-image-is-ratio-size{align-self:stretch;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col > .wp-block-kadence-advancedgallery{align-self:stretch;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column465357_a378ee-2f{position:relative;}@media all and (min-width: 1025px){.wp-block-kadence-column.kb-section-dir-horizontal>.kt-inside-inner-col>.kadence-column465357_a378ee-2f{-webkit-flex:0 1 558px;flex:0 1 558px;max-width:unset;margin-left:unset;margin-right:unset;}}@media all and (max-width: 1024px){.kadence-column465357_a378ee-2f > .kt-inside-inner-col{flex-direction:column;justify-content:center;align-items:center;}}@media all and (max-width: 767px){.wp-block-kadence-column.kb-section-sm-dir-vertical:not(.kb-section-sm-dir-horizontal):not(.kb-section-sm-dir-specificity)>.kt-inside-inner-col>.kadence-column465357_a378ee-2f{max-width:558px;-webkit-flex:1;flex:1;margin-left:auto;margin-right:auto;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col{flex-direction:column;justify-content:center;align-items:center;}} View this post on Instagram A post shared by Kalie | Travel Mom Creator (@kontheinside) Meta’s response Meta launched Meta AI in April 2024 and has since built it into Facebook, Instagram, WhatsApp, and Messenger. It operates across Facebook, Instagram, and WhatsApp. The assistant can answer questions, generate images, and help users create or retrieve information. Meta admitted in a statement to the Verge : “The feature never should have prompted the individual with questions like that.” The company said the feature had “missed the mark” and that it had fixed the issue that caused Meta AI to suggest questions about personal topics. In a classic “yes, but” non-apology, a Meta spokesperson also pointed out that the AI only surfaced information drawn from posts the person asking could already access. Although that doesn’t seem to explain why it reportedly surfaced a photo she had deleted years ago. A pattern of Meta AI failures Meta AI hasn’t always respected privacy. In June last year, we reported that users were publicly sharing conversations, often without realizing it. A separate bug we reported the following month could have allowed people to view other users’ private Meta AI chats by simply guessing their IDs. Late last year, Meta also started targeting people with ads based on their Meta AI conversations. What can users do? Parents get understandably irate when they discover just how much sites like Facebook can learn about their kids. While Robins regularly posted pictures and videos of her children, she had no idea that the service could aggregate information from years of posts to profile them. She’s not alone. So what can people do about it? Perhaps the better question is: What should people not do? The clearest answer is not to post identifiable pictures of your kids (or other people’s) on social media. Not just to stop them being tracked in a privacy hellscape, but also to reduce the risk of even darker outcomes . Robins described what she planned to do next: “I’m done. I’m removing any identifiable pictures and videos of our kids.” She added that she’ll ask her friends to do the same because, if they don’t, Facebook would still be able to harvest her children’s pictures from their accounts and use them in the profiles it builds. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by  downloading Malwarebytes today .
malwarebytes.comSep 15, 2026extracted
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Hackers compromised the official HBO Max account on Reddit and used it in a malvertising campaign leading to a ClickFix landing page. During a 48-hour window, the attackers pushed 108 malicious advertisements across five lure groups as part of the campaign, tracked as PasteSwitch. Using the verified u/hbomax account, the threat actors targeted both macOS and Windows users and aggressively promoted a native macOS application for HBO Max, which does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also contained a download button. “The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim’s control,” ADAMnetworks explains. On macOS, the attack relied on curl | zsh commands to deliver malware such as MacSync, AMOS Helper, fake wallet applications, and other malicious code to steal users’ information, including their credentials, messages, browser information, and cryptocurrency wallet information, and gain persistent access to their machines. On Windows, the attack relied on MSHTA and PowerShell to deliver the Amatera Stealer and achieve persistence. Configured for manual credential validation, the malware would bypass network telemetry by spoofing Facebook connections to hide its command-and-control (C&C) communication. The PasteSwitch campaign also used AnimateClipper and ZigClipper as persistent clipboard replacement tools to swap cryptocurrency addresses when users attempted to make a transaction, HudsonRock notes. According to the security firms, the clipboard stealers use a C&C hosted on the blockchain. The infrastructure was likely set up over a year ago and has been used in attacks since early 2026. Reddit was notified of the malicious activity associated with the official HBO Max account and immediately suspended the ads. SecurityWeek has emailed Warner Bros., which owns HBO Max, for a statement on the hack and will update this article if the company responds. Related: Personal, Financial Info Exposed in Revolut Data Breach Related: Telus Warns Customers of Account Breaches Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
securityweek.comSep 15, 2026extracted
Ciberataque contra el Landesnetz de Berlín y publicación de datos sustraídos
Ciberataque contra el Landesnetz de Berlín y publicación de datos sustraídos 15/09/2026 Mar, 15/09/2026 - 09:51 Entre el 7 y el 12 de agosto de 2026 se produjo el principal flujo de datos desde sistemas de dos administraciones del Gobierno regional de Berlín: la Senatsverwaltung für Mobilität, Verkehr, Klimaschutz und Umwelt y la Senatsverwaltung für Stadtentwicklung, Bauen und Wohnen. El incidente fue detectado durante investigaciones forenses y, el 14 de agosto, ambas administraciones fueron desconectadas preventivamente del Landesnetz para evitar una posible propagación. El Gobierno de Berlín hizo público el incidente el 17 de agosto, cuando todavía no había concretado su alcance. Posteriormente, las investigaciones confirmaron que se había producido una extracción de datos antes de la desconexión de los sistemas.  Tras el acceso, el grupo criminal Rhysida asumió la autoría y afirmó haber sustraído aproximadamente 5,7 TB de información, aunque esta cantidad fue inicialmente una afirmación únicamente de los atacantes. El grupo exigió al Gobierno de Berlín 30 bitcoins, unos dos millones de euros, a cambio de no publicar los datos, pero las autoridades rechazaron el pago. El 4 de septiembre los atacantes comenzaron a publicar los datos en la Darknet y posteriormente, difundieron un nuevo paquete el 6 de septiembre, que incluía credenciales de acceso. El Gobierno de Berlín estableció una unidad central de coordinación para revisar, verificar y evaluar la información publicada, con participación del LKA, las dos administraciones afectadas, la autoridad de protección de datos y otros organismos de seguridad; además, se adoptaron medidas adicionales tras la aparición de las credenciales.  A fecha de 10 de septiembre de 2026, el Gobierno de Berlín mantiene abiertas las investigaciones forenses y el análisis de los datos publicados, por lo que todavía no existe una identificación completa de toda la información afectada. La Administración señala que los datos corresponden principalmente a información no estructurada almacenada en directorios compartidos y personales de empleados de las administraciones afectadas, y que pueden existir datos personales de empleados, ciudadanos y empresas; la propia administración ha indicado que no puede pronunciarse todavía sobre documentos concretos hasta finalizar el análisis. No existen, según el estado comunicado oficialmente, indicios de que el Landesnetz continúe infiltrado, mientras que las personas identificadas como afectadas serán notificadas conforme a la normativa de protección de datos. El 10 de septiembre se habilitó además un punto central de contacto para ciudadanos y empresas afectados.    Referencias 17/08/2026 Land Berlin IKT-Vorfall im Landesnetz Berlin 17/08/2026 Berliner Zeitung Bau- und Verkehrsverwaltung in Berlin nach Hackerangriff vom Landesnetz isoliert 26/08/2026 Land Berlin Mehr Daten beim IKT-Vorfall abgeflossen 05/09/2026 Euronews Las 8 preguntas y respuestas clave del ciberataque y filtración de datos en Alemania Etiquetas Administración pública Cibercrimen Fuga de información
incibe.esSep 15, 2026extracted
Un solo impiegato con uno stipendio di 1,5 miliardi di dollari! Questa è la nuova élite dell’AI
Dentro le grandi aziende che stanno costruendo l’ intelligenza artificiale , c’è una categoria di professionisti che vale più di interi team: ricercatori, ingegneri e scienziati capaci di spingere oltre i limiti dei modelli di AI, progettando architetture, algoritmi e tecniche che possono determinare il futuro di un’intera azienda di miliardi di dollari di fatturato . Sono pochissimi, vengono corteggiati dai colossi della Silicon Valley e queste persone possono ricevere compensi che fino a pochi anni fa erano impensabili. Attenzione, non si tratta di normali sviluppatori: sono alcune delle menti più rare e contese dell’industria tecnologica, generalmente scienziati, statistici e matematici. Perchè alla base dell’ Intelligenza artificiale c’è la statistica e la matematica e queste menti brillanti e rare sono alcune tra le professioni più contese e remunerative al mondo. Le aziende di AI sono disposte a mettere sul tavolo stipendi, bonus, azioni e pacchetti pluriennali da centinaia di milioni di dollari pur di assicurarsi queste persone . Ma non è un mercato nel quale basta avere esperienza: servono capacità matematiche, scientifiche e informatiche fuori dal comune, oltre alla capacità di inventare ciò che ancora non esiste . Per questo, mentre milioni di persone cercano di capire come l’AI cambierà il proprio lavoro, una ristrettissima élite di ricercatori sta diventando uno degli asset più preziosi delle stesse aziende che l’AI la stanno costruendo. E quindi arriviamo al caso di Andrew Tulloch, il quale ci racconta perfettamente quanto sia diventata estrema questa competizione. Da Meta se n’è andato il ricercatore australiano a cui, durante una trattativa per riportarlo nell’azienda, sarebbe stato offerto un pacchetto di compensi da 1 miliardo di dollari , che avrebbe potuto raggiungere 1,5 miliardi di dollari considerando bonus e crescita delle azioni nell’arco di almeno sei anni. Una cifra mostruosa, destinata a una singola persona, che mostra quanto oggi una mente considerata eccezionale possa valere per un’azienda che combatte per conquistare la leadership nell’intelligenza artificiale. Da Meta se n’è andato il ricercatore Andrew Tulloch , a cui durante le trattative era stato offerto un compenso colossale – fino a 1,5 miliardi di dollari. Ha accettato con condizioni che non sono state divulgate, ma non ha lavorato nel gigante dei social network nemmeno un anno, riferisce Wall Street Journal citando fonti informate dei fatti. Il signor Tulloch ha annunciato la sua uscita da Meta il giorno prima, il 9 settembre. Non ha specificato dove andrà a lavorare in futuro e non ha risposto alle richieste dei giornalisti e in Meta hanno rifiutato di fare commenti. L’australiano Andrew Tulloch ha concluso con risultati eccellenti gli studi presso l’Università di Sydney e ha lavorato in Meta (all’epoca Facebook) nel campo del machine learning . Nel 2016, e in una all’ora sconosciuta startup OpenAI che aveva cercato di convincerlo a unirsi a loro. Il ricercatore aveva rifiutato, anche a causa dello stipendio basso: in Facebook era di 800.000 dollari, mentre gliene avevano offerti tre volte di meno. Nel 2023 ha accettato di passare a OpenAI, quando ChatGPT era già stato lanciato. Nel 2025 è passato a lavorare nello startup Thinking Machines Lab. Ad agosto dello stesso anno, Mark Zuckerberg ha cercato di convincere Tulloch a tornare nella sua azienda e gli ha offerto un pacchetto di compensi del valore di 1 miliardo di dollari, che con i bonus massimi e la crescita delle azioni in almeno sei anni avrebbe potuto raggiungere 1,5 miliardi di dollari. Inizialmente il ricercatore aveva rifiutato, ma dopo alcuni mesi ha accettato per una somma che non è stata mai resa pubblica. Dopo di che in Meta non ha lavorato nemmeno un anno. L'articolo Un solo impiegato con uno stipendio di 1,5 miliardi di dollari! Questa è la nuova élite dell’AI proviene da Red Hot Cyber .
redhotcyber.comSep 11, 2026extracted
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their release. One aspect worth highlighting is that users cannot leave public reviews or star ratings for apps that are available in Early Access. This has opened the door to a new kind of abuse where threat actors are pushing thousands of Early Access applications with deceptive content, including fake casino games and reward apps, as well as misleading utilities and titles that may infringe on third-party trademarks. Among the identified apps is a Grand Theft Auto imitator named "Vice Streets: Open World" (APK package:com.gamblechaos.withfriends.game), which has more than 1 million downloads. The game has no reviews or ratings. It's currently no longer available on the Google Play Store, although it's not clear if it was taken down by Google or by the uploader themselves. "The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted," Bitdefender said in a statement. Because users cannot leave critical reviews or poor ratings, the traditional trust signals no longer apply, allowing such apps to gain traction. These apps are said to be promoted through TikTok, Facebook, and other social media platforms using bogus ads that include videos featuring celebrity deepfakes generated using artificial intelligence (AI). "A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot," the Romanian cybersecurity company said in a report shared with The Hacker News. "Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive." The end goal is to generate illicit revenue by serving ad after ad. Another advantage that these Early Access casino-oriented apps have is that they allow them to sidestep many of the regulatory requirements legitimate gambling applications are required to comply with. To get around the licensing, geofencing, and age verification restrictions, the casino-style apps masquerade as casual slot and puzzle games and are aggressively promoted via ads on social media platforms that lead unsuspecting users to Early Access apps in the Google Play Store or directly to various gambling websites. Further analysis indicates that the lures used for these apps go beyond casino games, slot machines, and fake reward apps to include PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games. "Google's Early Access program remains a valuable tool for developers testing new ideas," Bitdefender said. "Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community's strongest defenses against deceptive software." The Hacker News has contacted Google for comment, and we will update the story if we hear back. The disclosure coincides with the emergence of multiple malware families targeting Android - Hagaseca, a remote access trojan spread via the THost9 loader that contains a worm component, which scans exposed Android Debug Bridge (ADB) services and installs the malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules. Mantax Otax, a hybrid mobile malware that brings together comprehensive spyware capabilities and ransomware functionality, allowing the operator to steal sensitive data, encrypt it on targeted older Android versions (Android 9 or earlier), and demand a ransom payment by locking the device screen. Language indicators and files from the victims suggest the activity is primarily focused on Indonesian targets. StreamRat, which abuses Android's accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest sensitive data. The malware targets Spanish-speaking users through Meta and TikTok ads to direct users to counterfeit sites by masquerading as a free TV-streaming service named StreamTV Esp. The development also coincides with GoldFactory's use of the Gigabud banking trojan to install a companion Android app called Vwork, a weaponized fork of Shelter, to clone a target app inside a work profile with the goal of conducting financial fraud. Similar vi "With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim's phone while a black screen hides what is happening," Group-IB said. "A cloned environment is used to evade fraud protection controls."
thehackernews.comSep 10, 2026extracted
Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Google Play’s Early Access program for Android apps allows developers to gather useful feedback from early adopters for app improvement before final release. It lets users try unreleased, in-development apps or games before their official public launch. The conversation is from user to developer, not between users. The program consequently includes no facility for inter-user recommendations, ratings or warnings. Dubious actors are exploiting this lack of public ratings and reviews by adding deceptive apps to the program, and then driving users through external advertising to download apps directly from the Early Access program. A typical process, outlined by Bitdefender, is for an app to be ‘advertised’ through TikTok or Facebook with promised cash rewards (PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots). But after installation, the promised payout never arrives. “Instead,” warns Bitdefender, “the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.” An example type of deceptive app is described as a ‘ghost casino’. While legitimate gambling acts are subject to strict regulation, many early access casino-style apps avoid the regulations by resembling casual slot games or puzzle products. Potential users are directed toward them by the fake social media ads. “Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free,” adds Bitdefender, noting that there are also ‘random user’ adverts. Social media has become adept at recognizing and removing these misleading adverts, but the process is easily repeatable and common enough for innocent users to be caught. Two of the most common sham titles used in this scheme are Chicken Road (a risk-and-reward mini-game where players guide a cartoon chicken across a hazardous path) and Ice Fishing (a fast-paced live dealer casino game), or variants on those names. Trademark abuse is also common, and Grand Theft Auto (GTA) is an example. The deceptive app is uploaded but named, for example, ‘Grand Theft Auto V (Early Access)’. After it has been indexed by Google Search, it is renamed – but any user searching for information on the product in question would be directed to the deceptive app. “Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.” Bitdefender’s research suggests this is a widespread problem, with some developers appearing multiple times, and some listings showing thousands of installs. The process is not using Coogle’s Early Access to deliver malware. Nor are the deceptive app developers being accused of anything clearly illegal (although fraud comes to mind). But it is nevertheless a clear misuse of a beneficial Google service, designed to benefit genuine app developers, being abused by deceitful developers. They benefit from the sale of advertisements, and they trick people into providing the hardware, possibly on a massive scale, to do so. Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps Related: Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play Related: 300 Malicious ‘Vapor’ Apps Hosted on Google Play Had 60 Million Downloads Related: North Korean Hackers Distributed Android Spyware via Google Play
securityweek.comSep 10, 2026extracted
Operación internacional para interrumpir la infraestructura del botnet Sality
Operación internacional para interrumpir la infraestructura del botnet Sality 10/09/2026 Jue, 10/09/2026 - 11:33 El 31 de agosto de 2026 se llevó a cabo una operación internacional dirigida contra la infraestructura de la botnet Sality, una red P2P utilizada durante más de dos décadas para distribuir cargas maliciosas en equipos comprometidos. La operación estuvo liderada por autoridades estadounidenses y contó con la participación de organismos de Bulgaria, Hungría y Rumanía, con el apoyo de Europol, Eurojust y empresas privadas especializadas en ciberseguridad. Sality había estado activo desde al menos 2003 y, según Europol, en su momento de mayor actividad podía proporcionar a sus operadores acceso a hasta un millón de equipos infectados; a lo largo de los años se asociaron más de 11 millones de direcciones IP únicas con su infraestructura. La actuación se dirigió contra los equipos que formaban parte de la infraestructura P2P de Sality y contra los dominios empleados por la botnet . Las autoridades estadounidenses incautaron dominios vinculados a Sality en EE. UU., mientras que las autoridades de Bulgaria, Hungría y Rumanía actuaron sobre infraestructura adicional localizada en Europa. Paralelamente, CrowdStrike y la Shadowserver Foundation proporcionaron capacidades de inteligencia y análisis técnico y ejecutaron una operación de sinkholing P2P, mediante la cual las comunicaciones de los equipos infectados fueron redirigidas desde la infraestructura criminal. Esta actuación permitió aislar los dispositivos comprometidos y dejar inoperativa la capacidad de comunicación utilizada por el operador. Shadowserver comenzó además a colaborar con proveedores de servicios de Internet y equipos de respuesta a incidentes para identificar sistemas infectados y facilitar la notificación y remediación de las víctimas. Según la información publicada por Europol y los organismos participantes, la operación ha conseguido interrumpir la infraestructura de Sality y dejar inoperativo su canal de control, pero esto no equivale a que el malware haya sido eliminado automáticamente de todos los equipos que habían sido infectados. Las organizaciones participantes mantienen actuaciones destinadas a identificar las infecciones y facilitar la remediación de los sistemas afectados. Europol señala además que la operación es el resultado de varios años de cooperación internacional y que desde 2017 había apoyado a las autoridades en la identificación y desmantelamiento progresivo de componentes de la infraestructura de Sality. En consecuencia, el estado comunicado oficialmente es el de una infraestructura criminal interrumpida, con los equipos que permanecían infectados aislados de la infraestructura del operador y con actuaciones de identificación y remediación de las víctimas todavía en curso.   Referencias 31/08/2026 CrowdStrike Peer Pressure: Inside the Sality Botnet Disruption Operation 01/09/2026 U.S. Department of Justice Sality Malware Disrupted in International Cyber Takedown 01/09/2026 Reuters Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say 02/09/2026 Europol Global public-private operation disrupts Sality botnet active for two decades Etiquetas Botnet Ciberdelito
incibe.esSep 10, 2026extracted
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
Meta launched on Tuesday a personal artificial intelligence agent, Muse, for people 18 and over who are looking for help with day-to-day tasks like schedules, shopping and, in the company’s words, turning “long-term goals into action plans.” The parent company of Instagram and Facebook is stressing the safety and privacy features of the agent, which for now is only available in the U.S. Muse, Meta said, runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. People can message the agent in a separate app, called Muse, or message it in WhatsApp. It can handle simple tasks like sending an email or booking travel, or bigger, long-term goals like creating a yearlong exercise plan or setting up a new business. “Once a person shares a goal with Muse, it helps them develop a personalized plan and coordinate their time and resources, then advances the work on its own. It can open a browser, fill out forms, and negotiate on their behalf,” Meta said in a blog post. Tech companies are touting AI agents as the next step after chatbots, which can answer questions and retrieve information but won’t take action on the user’s behalf. At its most basic level, an AI agent works like a traditional, human-crafted computer program that executes a job, like launching an application. Combined with an AI large language model, however, it can search for knowledge that enables it to complete tasks without explicit, step-by-step instructions. That means, instead of just helping you draft the language of an email, it can theoretically handle the whole process — receiving a message from your coworker, figuring out what you might want to say, and firing off the response on its own. For Meta, the agent fits into CEO Mark Zuckerberg’s vision of AI superintelligence that’s available to “everyone.” He outlined his vision last month in a 6,500-word essay published online. In the document derided by critics as fantastical, Zuckerberg said his company is working toward an era where everyone will have the tools to create new businesses, receive Ph.D.-level tutoring and provide personalized lifestyle tips. “Everyone will have an exceptionally capable personal agent that understands you, your goals, and everything you care about. Your agent will work 24/7 on your behalf to improve your relationships, health, career, finances, home management, hobbies, and more,” Zuckerberg wrote. “It will free up time for the things you enjoy, and help you accomplish more than you could otherwise.” Related: The Hidden Instructions That Can Hijack AI Agents Related: Meta AI Hacked External Systems During Cybersecurity Testing
securityweek.comSep 9, 2026extracted
Tor Browser: cos’è, come funziona e come navigare nel Dark Web in sicurezza
Tor non è sinonimo di Dark Web. È innanzitutto una rete progettata per rendere più difficile ricostruire l’origine e la destinazione delle comunicazioni online, proteggendo privacy e anonimato attraverso un’infrastruttura distribuita di relay e una cifratura a più livelli. È però anche la tecnologia che consente di raggiungere i servizi con dominio .onion, ed è proprio questa caratteristica ad averne legato nell’immaginario collettivo il nome alla parte più nascosta della Rete. A distanza di anni dalla sua nascita, Tor continua intanto a evolversi: cambiano il browser, le tecnologie per aggirare la censura e le difese della rete, ma non cambia una regola fondamentale. Anonimato non significa invulnerabilità e la sicurezza dipende tanto dalla tecnologia quanto dal comportamento di chi la utilizza. Indice degli argomenti Navigazione anonima e Dark Web: di cosa parliamo Cominciamo innanzitutto col dire che la navigazione nel Dark Web è sostanzialmente diversa dalla navigazione in incognito (detta anche navigazione privata) che viene offerta come opzione su tutti i browser. È bene puntualizzare questo argomento, oggetto di alcune false credenze: la navigazione in incognito ha semplicemente il vantaggio di non salvare la cronologia di navigazione, i cookie e i dati dei siti e le informazioni inserite nei moduli dei siti. Ma è molto lontana dal garantire un reale anonimato al navigatore. Questi viene tracciato comunque dal provider dei servizi Internet, che conosce il suo indirizzo IP e può identificare la sua posizione. Potrebbe essere tracciato anche dal datore di lavoro (o comunque da chi gli fornisce gli strumenti per navigare). Inoltre, la navigazione in incognito non ci permette in alcun modo di entrare nel Dark Web, che rappresenta un mondo a parte rispetto al Web che tutti noi navighiamo. Deep Web e Dark Web non sono la stessa cosa Prima di “entrare” nel Dark Web è necessaria un’ulteriore puntualizzazione su cosa sia realmente il Dark Web, che molto spesso viene confuso con il Deep Web. Sono due mondi molto diversi e in un certo senso non comunicanti tra loro. Tutti noi navighiamo tutti i giorni nel Deep Web: questa definizione indica l’insieme delle pagine presenti sul web e non indicizzate dai comuni motori di ricerca (ad es. Google, Bing ecc.): ne fanno parte nuovi siti, pagine web a contenuto dinamico, web software, siti privati aziendali, reti peer-to-peer. L’opposto del Deep Web si chiama Surface Web (o Visible Web o Indexed Web): sono le pagine indicizzate dai motori di ricerca. Quindi, Deep e Surface Web sono due aree dello stesso mondo, con la discriminante che la prima non è indicizzata (quindi potremo raggiungerla solo se ne conosciamo l’URL). È Deep Web la pagina del nostro profilo Facebook, così come la pagina web della nostra casella Gmail e i siti dei Cloud Service Provider dove sono archiviati i nostri file. Oppure le tante pagine aziendali, governative, finanziarie ad uso interno, presenti sul web, ma non indicizzate. L’immagine seguente, dove il web nella sua totalità è rappresentato come un iceberg, illustra in modo efficace questi concetti. Il Dark Web è invece una frazione molto piccola del web: un mondo separato e poco accessibile, che si appoggia sulle Darknet, che sono reti chiuse. Per accedervi sono necessarie particolari configurazioni, come vedremo in seguito. Le principali Darknet sono: Freenet (ormai poco usata), I2P ed in particolare proprio Tor (The Onion Router), che è ormai diventata la più famosa e usata tra queste reti. Navigare nel Dark Web, dunque, non ha nulla a che vedere con la navigazione in incognito dei browser. I browser tradizionali, infatti, non permettono di accedere al Dark Web. Per entrare nel Dark Web servono strumenti (browser) appositi. Il browser più noto ed utilizzato è Tor: vediamo ora di conoscerlo meglio e di capire come usarlo, precisando che navigare nel Dark Web non è illegale, salvo che non lo si utilizzi per azioni illecite. Cos’è il browser Tor La Darknet Tor esiste perché è stata costruita un’infrastruttura hardware, costituita dai server che la ospitano. La rete Tor è stata creata dalla US Navy nel 1998 utilizzando la tecnologia onion routing sviluppata per garantire l’anonimato sulle reti di computer. Nel 2006 è stata resa di pubblico dominio e nello stesso anno è nata Tor Project Inc., che è un’organizzazione no profit con sede in USA. Secondo la legge americana è classificata come organizzazione 501(c)3, cioè un’organizzazione senza fini di lucro che gode delle esenzioni fiscali che si applicano agli enti dedicati esclusivamente a fini religiosi, di beneficenza, scientifici, letterari o educativi. Tor Project è formato da una pluralità di organizzazioni, tra le quali figurano l’US Department of State Bureau of Democracy, lo Human Rights e il Labor, uno dei maggiori sostenitori del progetto. È supportata fin dalla sua nascita anche dalla Electronic Frontier Foundation (EFF). I molti finanziatori (sponsor) di Tor sono elencati sul sito di Tor Project. Tra le organizzazioni che sostengono Tor ci sono anche istituzioni del governo USA, quali la DARPA (Defense Advanced Research Projects Agency). Quindi è del tutto evidente come Tor Project non sia un’associazione clandestina o – ancor peggio – finalizzata al crimine informatico. È anzi uno strumento che – come si può leggere nel sito: “Defend yourself against tracking and surveillance. Circumvent censorship”. Per questi motivi, Tor è una rete di comunicazione usata da giornalisti, attivisti politici e whistleblowers per aggirare la censura e la sorveglianza nei paesi meno democratici. Il fatto che sia usata anche dai “cattivi” non ne inficia il valore. Il browser Tor è utilizzabile anche da chiavetta USB o da CD, senza bisogno di installare nulla. Tor non è una tecnologia rimasta immobile. L’aggiornamento continuo del browser rappresenta una componente essenziale del suo modello di sicurezza, perché l’anonimato offerto dalla rete perderebbe gran parte del proprio valore se il software utilizzato dall’utente presentasse vulnerabilità sfruttabili per comprometterne il dispositivo o identificarlo. A settembre 2026 Tor Project ha rilasciato la versione 15.0.22 di Tor Browser, aggiornando anche il componente Tor sottostante. Gli aggiornamenti precedenti avevano inoltre incorporato nuove versioni di Firefox ESR, OpenSSL e NoScript insieme alle relative correzioni di sicurezza. È un aspetto da non sottovalutare: usare Tor Browser senza mantenerlo aggiornato può vanificare una parte delle protezioni che la stessa architettura Tor cerca di offrire. Parallelamente sta evolvendo anche il cuore tecnologico della rete. Tor Project lavora da tempo ad Arti, implementazione di nuova generazione di Tor scritta in Rust. Con Arti 2.6.0, pubblicato nel settembre 2026, il progetto ha compiuto ulteriori passi verso il suo utilizzo come relay e directory authority, integrando anche evoluzioni nel controllo della congestione e nelle difese crittografiche. L’obiettivo di lungo periodo è quindi più ampio del semplice aggiornamento del browser: modernizzare progressivamente l’infrastruttura Tor e renderla più robusta rispetto a vulnerabilità, attacchi e nuove tecniche di analisi del traffico. I numeri della rete Tor: un’infrastruttura globale Misurare con precisione quanti utenti utilizzino Tor non è semplice, proprio per la natura della rete. Tor Project pubblica tuttavia attraverso Tor Metrics stime elaborate analizzando le richieste generate dai client verso relay e bridge. I dati mostrano una rete utilizzata su scala globale, con centinaia di migliaia di connessioni giornaliere provenienti dai principali Paesi. Ma il dato più importante va letto al di là dei numeri: utilizzare Tor non significa necessariamente navigare nel Dark Web. La rete viene infatti impiegata anche per raggiungere il normale Web cercando di ridurre tracciamento e sorveglianza, oltre che per aggirare blocchi e censura. Giornalisti, ricercatori, attivisti, whistleblower e cittadini che vivono in Paesi nei quali l’accesso a Internet è sottoposto a restrizioni rappresentano alcuni dei casi d’uso legittimi più significativi. Per questo, più che fotografare Tor attraverso un numero assoluto di utenti destinato inevitabilmente a cambiare nel tempo, è utile considerarlo come una vera e propria infrastruttura globale per la privacy e la libertà di accesso alle informazioni. Come funziona la rete Tor Per capire come usare Tor è necessario conoscere come è fatta la sua infrastruttura. La rete Tor è un network decentralizzato costituito da alcune migliaia di server (sono i “relay”: a publicly-listed server in the Tor network) sparsi nel mondo. In particolare, dovrebbero essere circa 6.000-8.000 i relay (nodi) e quasi 3.000 i bridge (ponti), quasi tutti gestiti da volontari. I dati di navigazione non transitano direttamente dal client al server, come accade per la navigazione normale. I pacchetti di dati passano invece attraverso i relay Tor che agiscono da router (chiamati anche “nodi”) e realizzano un circuito virtuale crittografato a strati (come una “cipolla”, da cui il nome Onion). Per questo motivo gli URL della rete Tor hanno il TLD (Top Level Domain) che non è il classico .com o .it, ma .onion. Quando si avvia la navigazione aprendo il browser Tor (spiegheremo più avanti come ottenerlo), questo sceglie dall’elenco Directory server una lista di nodi e da queste individua tre nodi (tre è la configurazione standard, salvo eccezioni che vedremo in seguito) in modo casuale, che costituiscono una catena di navigazione. Nella pagina del browser possiamo vedere – in tempo reale – il percorso (definito “circuito”) che viene fatto e anche cambiarlo con il pulsante che si trova alla sinistra della barra dell’URL. In ciascun passaggio, la comunicazione viene crittografata e questo si ripete per ciascun nodo (a strati come la cipolla). Ogni nodo della rete conosce solo il precedente e il successivo, nessun altro. Questo rende pressoché impossibile (o comunque molto complicato) risalire al client di partenza. Ci sono tre tipi di relay nel sistema di navigazione Tor: guard/middle relay; exit relay; bridge. Come abbiamo detto, per ragioni di sicurezza il traffico Tor passa attraverso almeno tre relay prima di raggiungere la sua destinazione. Il primo è il guard relay (o entry relay o “nodo di guardia”), il secondo è un middle relay (intermedio) che riceve il traffico e lo passa all’exit relay (figura sottostante). I relay intermedi (guard e middle) sono visibili solo all’interno della rete Tor e, a differenza del relay d’uscita, non fanno apparire il proprietario del relay come la fonte del traffico. Ciò significa che un relay intermedio è generalmente sicuro (lo potremmo avere anche nel server di casa nostra, partecipando così all’infrastruttura Tor). Il relay di uscita è l’ultimo nodo che il traffico Tor attraversa prima di raggiungere la sua destinazione. I servizi a cui i client Tor si connettono (sito web, servizio di chat, provider di posta elettronica ecc.) vedranno l’indirizzo IP del relay di uscita invece dell’indirizzo IP reale dell’utente Tor. In altre parole, è l’indirizzo IP del relay di uscita che viene interpretato come la fonte del traffico. Per questo motivo, è possibile incorrere in un inconveniente piuttosto buffo durante la navigazione: se il relay d’uscita si trova in Svezia, il sito che si sta consultando potrebbe presentarsi in lingua svedese, supponendo che sia questa la lingua del visitatore. Bridges (ponti) È importante sapere che la struttura della rete Tor prevede che gli indirizzi IP dei relay Tor siano pubblici. Ed uno dei modi in cui il Tor può essere bloccato dai governi o dagli ISP è quello di inserire nelle blacklist gli indirizzi IP di questi nodi Tor pubblici. Per questo esistono i Bridges: sono nodi che non sono indicati nell’elenco pubblico come parte della rete Tor, il che rende più difficile per gli ISP e i governi bloccarli. I bridges sono quindi strumenti essenziali per l’elusione della censura nei paesi che bloccano regolarmente gli indirizzi IP di tutti i relay Tor elencati pubblicamente, come Cina, Turchia e Iran. La rete Tor si affida a volontari che offrono i loro server e la loro banda: chiunque, quindi, può mettere a disposizione un proprio computer per creare un relay della rete Tor. L’attuale rete Tor è piuttosto sottodimensionata rispetto al numero di persone che la utilizzano, il che significa che Tor ha bisogno di più volontari per accrescere il numero dei relay. Gestendo un relay Tor, come viene spiegato nella pagina dedicata del sito Tor Project, si può contribuire a migliorare la rete Tor rendendola: più veloce (e quindi più utilizzabile); più robusta contro gli attacchi; più stabile in caso di interruzioni; più sicura per i suoi utenti (spiare più relay è più difficile che farlo su pochi). Per i motivi che abbiamo spiegato, un utente potrà fornire un relay di tipo guard/middle (cioè un non-exit Tor relay) mentre non è opportuno che attivi un exit relay perché più esposto. Per attivare un guard relay si deve disporre di una connessione stabile e veloce (almeno 2 MByte/s), altrimenti si potrà creare un middle relay, che è il nodo intermedio tra guard ed exit ed è quello che richiede i requisiti più ridotti: 10 Mbit/s (Mbps). Infine, è da considerare un aspetto peculiare di Tor, che rappresenta un problema non trascurabile: la sicurezza va a scapito della velocità. Il “giro del mondo” che dovrà fare il flusso dei dati (come abbiamo spiegato) renderà la navigazione inevitabilmente latenza introducendo overhead e latenza rispetto a una connessione diretta; ma occorre precisare che la prestazione effettiva dipende però da circuito, congestione, relay e destinazione. Inoltre, l’attuale rete Tor è sottodimensionata rispetto al numero di persone che cercano di usarla. Non bisogna quindi pensare di usare Tor per lo streaming, il file sharing o per attività che richiedano grandi flussi di dati. La partita tra strumenti di anonimizzazione e sistemi di censura della Rete è però in continua evoluzione. Bloccare gli indirizzi IP dei relay pubblici è infatti soltanto una delle tecniche con cui governi e provider possono cercare di impedire l’accesso a Tor. Per questo Tor Project sviluppa anche i cosiddetti pluggable transports, tecnologie progettate per rendere più difficile identificare e bloccare il traffico diretto verso la rete. Tra queste c’è WebTunnel, un particolare tipo di bridge che cerca di far apparire le comunicazioni Tor simili al normale traffico Web HTTPS. L’obiettivo è consentire alla connessione di confondersi con quella generata dalla normale navigazione, rendendo più complesso applicare blocchi selettivi senza interferire anche con servizi Web legittimi. Un’altra tecnologia è Snowflake, che utilizza proxy temporanei messi a disposizione da volontari per consentire agli utenti di raggiungere la rete Tor anche quando l’accesso diretto è sottoposto a restrizioni. Nel 2026 il progetto ha continuato a investire su entrambe le tecnologie, a conferma di come la capacità di aggirare la censura sia ormai una componente strutturale dell’evoluzione di Tor e, contemporaneamente, una sfida destinata a cambiare insieme alle tecniche utilizzate per identificarne e bloccarne il traffico. Iniziamo a navigare nel Dark Web: come installare Tor Browser Tor Project sconsiglia di usare Tor con altri browser perché “pericoloso e non raccomandato. Utilizzare Tor in un altro browser può farti rimanere vulnerabile e senza le protezioni privacy implementate in Tor Browser”. Tor Browser è una versione modificata di Firefox (utilizza Firefox ESR) progettata specificamente per essere utilizzata con Tor: dobbiamo quindi prima di tutto scaricare Tor Browser disponibile in 30 lingue diverse. Ogni file della pagina Download è firmato con OpenPGP: si può vedere il corrispondente file .asc, che è la firma OpenPGP, che permette di verificare che il file che abbiamo scaricato è esattamente quello da noi previsto. Tor Browser è disponibile per Windows, macOS, Linux e, da qualche tempo, anche per i dispositivi mobili. Per Android è possibile scaricare dal sito Tor Project il file .apk dell’applicazione, oppure più semplicemente andare sul Google Play Store e scaricare l’app ufficiale. Questa app rappresenta l’unico browser mobile ufficiale supportato e sviluppato dal Tor Project. Non è presente un’app ufficiale per iPhone: tuttavia, sul sito Tor Project, nella pagina dedicata alla versione Android del software, compare il messaggio: “Sei un utente iOS? Ti incoraggiamo a provare Onion Browser”, che rimanda all’applicazione consigliata Onion Browser che può essere scaricata direttamente anche da App Store. Peraltro, sul sito Tor Project compare anche questo avviso: “Noi raccomandiamo di utilizzare un’applicazione iOS chiamata Onion Browser: è open source, utilizza Tor ed è sviluppata da una persona che collabora strettamente con il Tor Project (Mike Tigas, sviluppatore e giornalista investigativo, n.d.A). Tuttavia, Apple richiede ai browser che girano su iOS di utilizzare una cosa chiamata Webkit, che impedisce a Onion Browser di avere le stesse protezioni per la privacy di Tor Browser”. Sia su Android che su iOS si trovano molte altre app non ufficiali di Tor Browser, che è sconsigliabile usare. L’installazione di Tor Browser è molto semplice ed assistita da un ampio tutorial presente sul sito ufficiale del progetto. Quando si avvia Tor Browser per la prima volta, compare la finestra Impostazioni di Rete Tor. Questa finestra permette di connettersi direttamente alla rete Tor o di personalizzare la configurazione di Tor Browser. Nella maggior parte dei casi, è sufficiente cliccare su Connetti e collegarsi alla rete Tor senza ulteriori configurazioni. L’opzione Configura diventa invece necessaria se ci troviamo in un paese che censura Tor (come Egitto, Cina Turchia) e se ci stiamo connettendo da una rete privata che richiede un proxy. Poiché l’accesso diretto alla rete Tor a volte può essere bloccato dal fornitore di servizi Internet o da un governo, Tor Browser include alcuni strumenti di elusione per aggirare tali blocchi. Questi strumenti sono chiamati pluggable transports. In ogni caso, è possibile anche settare il livello di protezione, cliccando sull’icona a forma di scudo che si trova in alto a sinistra e selezionando Impostazioni di Sicurezza Avanzate. Nella schermata che appare potremo scegliere tra i livelli Standard, Sicuro e Molto sicuro. Livelli di sicurezza alti possono causare problemi di funzionamento di Tor Browser: più alto il livello, più limitata sarà anche inevitabilmente l’esperienza di navigazione. Navigare con Tor Browser Una volta installato Tor Browser, siamo pronti per iniziare a navigare nel Dark Web. Ovviamente possiamo utilizzarlo anche come un normale browser per accedere ai siti del surface web. Tor riduce la possibilità di ricondurre la connessione all’indirizzo IP dell’utente. Nella pagina del browser possiamo vedere – in tempo reale – il percorso (definito “circuito”) che viene fatto: è sufficiente cliccare sull’icona posta a sinistra della barra della URL. Di regola la lunghezza del percorso è impostata a 3, più il numero di nodi che durante il percorso sono sensibili. Ciò significa che normalmente i nodi sono 3 (se siamo su un sito del surface web), ma se – per esempio – si accede ad un servizio .onion o ad un indirizzo “.exit” potrebbero essercene di più (e li vedremo indicati nel circuito con il termine “ripetitori”). Con l’opzione Nuovo Circuito potremo anche cambiare il percorso, sempre cliccando sul pulsante che si trova alla sinistra della barra della URL. Non possiamo stabilire noi i relay, ma solo fare in modo che Tor ne scelga altri tre. Questo serve se l’exit relay che stiamo utilizzando non è in grado di connettersi al sito che visitare, o non lo sta caricando correttamente. Selezionando questa opzione si ricaricheranno tutte le schede attive o le finestre utilizzando un nuovo circuito Tor. Un’altra opzione che potremmo usare è Nuova Identità (disponibile dal menu in alto a destra rappresentato da un’icona con tre linee orizzontali). Questa è utile se si vuole evitare che le successive attività del browser siano correlabili a quanto fatto in precedenza. Selezionando questa opzione, si chiuderanno tutte le schede e le finestre, si puliranno le informazioni personali come i cookie e la cronologia di navigazione e verrà instaurato un nuovo circuito Tor per le connessioni. Tor Browser avviserà che tutte le attività e i download saranno interrotti e le sessioni aperte andranno perse. Con Tor Browser possiamo – soprattutto – accedere al Dark web dove, invece, non è possibile utilizzare i browser classici, quali Chrome, Safari, Firefox: digitando su questi una URL .onion non avremo nessuna risposta. Una volta entrati con Tor nel Dark Web, si potrà navigare tra i vari siti, di cui ovviamente bisogna conoscere gli indirizzi. Fra questi siti si può trovare di tutto, inclusi mercati della droga, killer a pagamento, comunità di vario tipo; ma si trovano anche molti siti presenti già sulla Rete in chiaro. La garanzia dell’anonimato rende la navigazione su Tor Browser molto utile e molto sicura in paesi con regimi autoritari. Permette a gruppi di opinione, dissidenti e attivisti politici di comunicare tra loro senza rischiare di essere controllati ed intercettati dai governi e dalle polizie. Lo prova il fatto che nella rete Tor non si trovano solo siti clandestini o illegali: abbiamo anche le versioni .onion di siti famosi. Esiste, per esempio, il sito Tor del The New York Times (dal 2017, ma non funziona con i browser abituali, solo con Tor browser). Provando ad accedere alla sua home page e alle pagine interne, troveremo esattamente il sito ufficiale del New York Times, semplicemente ospitato nel Dark Web. La stessa cosa vale per il sito di BBC News o per Facebook. Ed infine il sito di Tor nella rete Tor. Perché esistono? Proprio per permettere di accedere a Facebook o leggere il New York Times in quei paesi dove questi siti sono “bannati” e quindi non accessibili. Consigli per navigare nel Dark Web C’è il rischio di rimanere delusi dal Dark Web, scoprendo che è un luogo ben più modesto di quello che si racconta e si favoleggia. Il Dark Web è molto piccolo: si ritiene (ma è una stima molto approssimativa) che contenga non più di 100.000 siti, che rappresentano probabilmente meno dello 0,005% delle dimensioni dell’intero World Wide Web. In realtà, i siti .onion attivi potrebbero essere ancora meno: si tratta in genere di siti che sono molto “volatili”, perché nascono e spariscono rapidamente (spesso chiusi dalla polizia). Quindi difficili da censire. Ha provato a farlo Recorded Future: dal punto di vista linguistico, i siti Tor (.onion) sono più omogenei del web di superficie con l’86% dei siti che ha l’inglese come lingua principale, seguita dal russo con il 2,8% e il tedesco con l’1,6%; numeri di visite: mentre nel web di superficie, i siti più popolari attirano milioni di visite, nei siti .onion quello con il più alto numero di link in entrata è stato un black market con circa 3.585 link in entrata; vita media dei siti .onion: i risultati di un rapporto di Onionscan del 2017 riporta che su 30.000 siti interrogati, poco più di 4.400 erano effettivamente online. Anche se queste analisi hanno un livello di incertezza elevato, possiamo dire che il “rapporto tra vivi e morti” continua ad essere simile a quello di altre ricerche precedenti, con appena il 15% dei siti .onion in vita. Meglio utilizzare un computer secondario, nel quale non abbiate in archivio documenti e informazioni importanti (non si sa mai…). Usare esclusivamente Tor Browser. Il browser Tor è basato su Firefox, questo permette di utilizzare add-ons e temi compatibili con Firefox anche nel browser Tor (dal menù delle Impostazioni in Estensioni e Temi). Tuttavia, gli unici componenti aggiuntivi che sono stati testati per l’utilizzo con il browser Tor sono quelli inclusi di default (HTTPS Everywhere e NoScript). È fortemente sconsigliato installare altri componenti aggiuntivi (estensioni) in Tor Browser, perché possono comprometterne la privacy e la sicurezza. Usare un motore di ricerca sicuro, come DuckDuckGo, che non traccia i suoi utenti né memorizza alcun dato riguardo le loro ricerche. È il motore di ricerca predefinito in Tor Browser. Tor Browser nella sua modalità predefinita inizia con una finestra arrotondata a un multiplo di 200px x 100px per impedire l’impronta digitale (fingerprint) delle dimensioni dello schermo. Evitare quindi di mettere la finestra a tutto schermo, per non agevolare la ricostruzione della fingerprint, che ci potrebbe individuare in modo univoco. Per lo stesso motivo sarebbe consigliabile impostare la lingua inglese (quella di default) invece dell’italiano. Come trovare i siti? Se non conoscete l’URL, potete utilizzare raccolte di indirizzi .onion che sono disponibili. Uno dei più conosciuti è The Hidden Wiki: . Un’altra raccolta (solitamente accessibile) è TorLinks. Ed anche TorGate – A Darknet Link Directory. Non sono sempre affidabili, perché – come abbiamo spiegato – i siti .onion nascono e muoiono molto velocemente, quindi i link indicati (anche quelli che trovate su The Hidden Wiki o su TorLinks), potrebbero non funzionare più. È una delle tante caratteristiche “scomode” del Dark Web… La navigazione potrebbe risultare frustrante perché molti siti linkati possono essere offline o non esistere più. Molti siti non sono liberamente accessibili, si può entrare solo se invitati. Ma non è un problema, lasciateli perdere. Non registrarsi con account di posta elettronica e non utilizzare nomi utente o nomi che possono essere utilizzati per identificarci. Eventualmente consiglio di creare una email temporanea con un nome utente di fantasia: esistono molti servizi web per questo. Si sconsiglia di usare Tor con BitTorrent. Evitare, ovviamente, di compiere nel Dark Web azioni illegali. Ed infine, meglio lasciar perdere la leggenda delle Red Room! Le Red Room sarebbero degli spettacoli di tortura in live streaming. Per assistere bisogna pagare cifre molto alte in Bitcoin. Non ci sono prove concrete che dimostrino l’esistenza delle Red Room e se ci fossero pagine web che si spacciano per “Stanze Rosse”, sarebbero probabilmente solo siti fake creati per spillare soldi. E poi, considerata la lentezza della navigazione, un filmato in streaming su Tor sarebbe impossibile da vedere. Quanto è sicuro e anonimo Tor? Tor aumenta significativamente la difficoltà di collegare un utente alla propria attività online, ma non deve essere interpretato come una garanzia assoluta di anonimato. L’architettura onion impedisce al singolo relay di conoscere contemporaneamente origine e destinazione della comunicazione, ma esistono altri livelli sui quali l’anonimato può essere compromesso: vulnerabilità del browser, malware sul dispositivo, errori dell’utente, autenticazione con account riconducibili alla propria identità, download e apertura di documenti con applicazioni esterne oppure avversari capaci di osservare porzioni sufficientemente ampie della rete. Anche il ruolo degli exit relay va interpretato correttamente. Quando si visita un normale sito Internet, l’exit relay rappresenta il punto in cui il traffico lascia la rete Tor. Se la connessione verso il sito utilizza HTTPS, tuttavia, il contenuto applicativo resta protetto dalla cifratura TLS tra browser e server. Per questo è importante verificare sempre l’uso di HTTPS e prestare particolare attenzione ai siti che richiedono credenziali o informazioni sensibili. Il rischio più concreto resta quindi quello di attribuire a Tor proprietà che non possiede. La rete può nascondere l’indirizzo IP di origine e rendere molto più difficile correlare sorgente e destinazione, ma non può proteggere un utente che rivela volontariamente la propria identità, utilizza software vulnerabile o porta fuori dal browser contenuti capaci di stabilire connessioni indipendenti. In altre parole, Tor offre anonimato a livello di rete, non l’invisibilità dell’utente. Ed è proprio questa distinzione che dovrebbe guidarne l’utilizzo in sicurezza.
cybersecurity360.itSep 9, 2026extracted
The push to stop algorithms controlling social media feeds has begun
Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants that internet back. Yesterday, the government released draft legislation outlining a Digital Duty of Care. The proposal includes a measure that Prime Minister Anthony Albanese labeled “My Feed, My Way.” It would allow Australians over 16 to switch off the algorithmic feed that social media platforms deliver automatically to users, instead allowing them to see content from friends and creators they choose to follow. This legislation, which is expected to reach Parliament before Christmas, would force platforms to send notifications to both new and existing users asking them to choose between the two types of feed. Platforms would then have to respect that choice unless the user changed it. The feed controls are grabbing the headlines, but the Digital Duty of Care also includes protections for users under 18. Digital services, including social media, online games, apps, and AI chatbots, would have to protect under-18s from harmful content and design features that could negatively affect their behavior or self-esteem. That includes content that promotes eating disorders, misogyny, crime, life-threatening stunts, pornography, or serious mental health distress. The proposed law is the latest move from a country known for its aggressive stance on social media safety. Australia banned under-16s from using a wide range of social media platforms, although it hasn’t gone that well. Three months after the December 2025 ban, 81% of Aussie kids were still using at least one restricted social media platform, down from 86% when the ban was introduced. Before the ban took effect, about 60% used social media at least once a day. Three months later, that figure was 58%. Bans sound good on paper but they’re hard to enforce . The new proposal takes a different approach by placing more responsibility on social media companies. The government promises penalties of up to $109.2 million Australian dollars (US$78.6 million) for companies that fail to comply with the Digital Duty of Care. The Australian eSafety Commissioner would also gain the power to issue removal notices for nudify apps and websites, and streamline its existing child cyberbullying and adult cyber abuse schemes so it can deal with harmful material more quickly. The move comes less than two weeks after Meta agreed to let teens choose a non-personalized feed as part of a multi-billion dollar settlement with US states. Why is an opt-out from automatically curated feeds important? Companies that automatically curate your content with their own algorithms tend to show you more of what you’ve been seeing. That can be great if you’re building a chicken coop and want as much advice as possible on nest box placement. But it can also narrow the range of content you see, making it harder to develop a well-rounded view of a subject. Perhaps sensing a change in the political wind, social media companies have already begun offering friends-only feeds. Facebook reintroduced this capability in its Friends tab in the US and Canada in March 2025. It called this one of its “OG” Facebook experiences. TikTok also now has a Friends tab alongside its regular For You feed, while Instagram has offered chronological Following and Favorites feeds since 2022. YouTube has its Subscriptions feed, while Snapchat created separate feeds for friends and other content creators back in 2017. The problem is that these feeds aren’t the default. Recommended content remains the easiest option to consume. If you use social media and want more control over what you see, look for its Friends, Following, Favorites, or Subscriptions feed. You might end up with more humblebragging , vaguebooking , or faux-wisdom memes, but at least you’ll know why you’re seeing them. And you can always get some new friends. Scammers don’t need to hack you. They just need you to click once.   Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
malwarebytes.comSep 9, 2026extracted
Acceso no autorizado a cuentas de Dropbox mediante una integración de Lenovo ID
Acceso no autorizado a cuentas de Dropbox mediante una integración de Lenovo ID 08/09/2026 Mar, 08/09/2026 - 09:33 Entre el 4 y el 21 de agosto de 2026 se produjeron accesos no autorizados a cuentas de Dropbox mediante el mecanismo de autenticación asociado a Lenovo ID. Dropbox identificó posteriormente que las cuentas afectadas estaban vinculadas a Lenovo ID y no tenían activada la autenticación de dos factores. Según la información facilitada por Dropbox, aproximadamente 5.000 cuentas resultaron afectadas durante ese periodo. El incidente no consistió en la obtención de las contraseñas de Dropbox, sino en el abuso de un mecanismo de autenticación federada entre Dropbox y Lenovo. Según la investigación comunicada por Dropbox, un problema en el proceso de verificación del correo electrónico de Lenovo ID permitió a terceros registrar una cuenta de Lenovo utilizando la dirección de correo electrónico de otra persona y utilizar posteriormente esa identidad para acceder a la cuenta de Dropbox asociada a la misma dirección. Dropbox indicó que menos de un tercio de las aproximadamente 5.000 cuentas afectadas registraron visualización o descarga de archivos. Lenovo, por su parte, describió el problema como una integración heredada entre Lenovo ID y Dropbox que podía utilizarse para autenticar indebidamente determinadas cuentas. Tras identificar el problema, Dropbox expiró todas las sesiones autenticadas mediante Lenovo ID, eliminó los vínculos entre las cuentas de Lenovo y Dropbox y modificó el proceso para exigir la contraseña de Dropbox antes de permitir el acceso mediante Lenovo ID. Asimismo, Dropbox notificó el incidente a los usuarios afectados y a los organismos reguladores de protección de datos. Actualmente, Dropbox considera mitigado el mecanismo de acceso utilizado durante el incidente: las sesiones autenticadas mediante Lenovo ID fueron cerradas, se eliminaron las vinculaciones existentes y se introdujo una comprobación adicional mediante la contraseña de Dropbox. La compañía comunicó directamente a los usuarios afectados la situación y señaló que quienes no hubieran recibido dicha comunicación no estaban incluidos entre las cuentas afectadas. Lenovo ha indicado que sus propios clientes no resultaron afectados y que su investigación continúa. Por tanto, de acuerdo con las últimas declaraciones disponibles de las compañías, el acceso mediante el mecanismo utilizado en el incidente ha sido bloqueado, mientras que la investigación de Lenovo sobre la integración afectada permanece abierta.   Referencias 31/08/2026 Dropbox Notificación de acceso no autorizado a cuentas entre el 4 y el 21 de agosto 01/09/2026 Reuters Dropbox says about 5,000 accounts compromised in August hack 01/09/2026 Decrypt Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw 02/09/2026 Lenovo Declaración sobre la integración heredada entre Lenovo ID y Dropbox Etiquetas Acceso no autorizado Intrusión Servicios almacenamiento
incibe.esSep 8, 2026extracted
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a technical report published last week. JSCeal was first documented by Check Point in July 2025, highlighting the threat actors' use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust. Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant disclosed details of a massive malvertising operation codenamed SourTrade, which has been observed impersonating trusted trading and cryptocurrency brands, such as Solana, Luno, and TradingView, to serve lookalike portals with malicious JavaScript that instructs web browsers to assemble malware directly in memory. The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America. Evidence indicates that the campaign overlaps with a JSCeal campaign described by Bitdefender in September 2025. "What makes SourTrade technically distinct is what happens on its landing page," Confiant said. "It does not distribute finished malware. Instead, it delivers assembly instructions to the victim's browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network." JSCeal is protected using javascript-obfuscator, with the operators repeatedly using four groups of transformations to obscure the malware. These include - Replacing function and variable names with short or nonsensical identifiers Splitting important strings into chunks (which are subsequently encoded and RC4-protected) and then reconstructing them through decoder functions Using control-flow flattening to turn program flow into a flat, single-level switch statement controlled by an infinite loop and a state variable with the goal of making analysis and reverse‑engineering harder Forwarding function calls through proxy helpers and wrapping simple operations, like addition, subtraction, comparison, or function invocation, in dedicated helper functions The Israeli cybersecurity company said it developed a "fully static deobfuscation pipeline" to decode compiled V8 JavaScript bytecode protected with the utility, thereby offering insights into the malware's execution flow and its features, counting its ability to enumerate installed browsers, and query saved secrets, cookies, OAuth tokens, and other data from them, as well as "router" functions that register handlers for the collected information. The browser stealing module targets a long list of Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc. For each browser, the malware navigates to the expected location of its user-data directory and lists available profiles, from where cookies and passwords are extracted. What's more, JSCeal is equipped to leverage the stolen cookie data to reconstruct a browser session and conduct active session replay attacks to bypass authentication and gain unauthorized access to a victim's Google account. A second module embedded within the malware offers surveillance capabilities by recording keystrokes and taking screenshots. "A common technique used by banking trojans is to install a local proxy and inject or modify web content in selected services," Check Point said. "JSCeal follows a similar pattern: the recovered code shows proxy setup, certificate generation and installation, and service-specific request and response modification." "The proxy is not limited to passive interception. The recovered code contains dedicated handlers that modify selected requests and responses for specific services. A configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies." There also exist multiple handlers specifically focused on cryptocurrency platforms, one of which captures account data and records cryptocurrency balances. "JSCeal combines two forms of analysis friction: a version-specific compiled V8 format and several layers of JavaScript obfuscation applied before compilation. Neither makes the malware impossible to reverse, but together they move it outside the workflows that analysts normally rely on," security researcher Aleksandra "Hasherezade" Doniec said. "Taken together, these developments show that the JSCeal authors are investing both in making the payload harder to analyze and in broadening its platform coverage. With campaigns continuing into recent months, the changes indicate that JSCeal remains under active development."
thehackernews.comSep 7, 2026extracted
StreamRat Android malware spreads through Meta and TikTok ads
A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections, but it demonstrates how quickly paid advertising can put a scam in front of a very large audience. The ads promoted an Android banking Trojan and infostealer called StreamRat . It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to steal usernames and passwords, and allow attackers to control the device remotely. We often warn people not to click suspicious links in unexpected texts or emails. But malicious advertising is harder to recognize because it appears in the same feeds where people expect to find promotions, videos, and recommendations. This campaign is a perfect demonstration of why “after-the-fact” ad checks are inadequate when it comes to protecting social media users. Attackers used familiar social media advertising and carefully tailored instructions to turn casual interest in free entertainment into a risky app installation. How the attack worked The ad led victims to a website posing as a streaming platform. The site checked whether a visitor was using Android. Non-Android visitors were simply prevented from downloading anything, while Android users were shown an app download option. This is a common way for scammers to concentrate their efforts on devices their malware can infect. The site also identified whether someone had arrived through Instagram, TikTok, Facebook, or a regular browser. It then displayed instructions suited to that situation, including steps to allow the browser to install apps from “unknown sources.” In other words, this was not a generic malicious download page: It was designed to coach people through the security warnings that would normally make them stop and think. StreamRat is an Android banking Trojan and infostealer. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to collect usernames and passwords, and enable attackers to operate the device remotely. The researchers also found options to cover the screen with a black page or fake Android update screen. These can distract victims while criminals interact with the phone behind the scenes. How to stay safe While this campaign targeted Spanish-speaking people, primarily in Spain, the following guidelines can help anyone avoid similar attacks. Avoid installing Android apps from ads, direct-download websites, social media messages, sponsored search results, or links sent by strangers. Download apps through Google Play whenever possible, and check the developer’s name, reviews, and app history rather than relying on an ad. Before enabling installation from “unknown sources,” read our guide, Sideloading on Android: What it is, why it’s risky, and how to do it more safely . Be very cautious when an app asks for Accessibility access, screen-sharing permission, Device Admin privileges, or permission to become the default launcher. Permissions that don’t line up with the intended use of the app are very suspicious. Use an up-to-date, real-time anti-malware solution on all your devices. What to do if you installed a suspicious app If you installed a suspicious APK and granted it Accessibility access, disconnect the phone from Wi-Fi and mobile data. If possible, revoke the app’s Accessibility access and remove it. Use another device to change relevant passwords and contact your bank if you used banking apps on the infected phone. A factory reset may be necessary if you cannot confidently remove the infection. Malwarebytes for Android detects StreamRat as Android/PUP.Agent.ACR02DB0614H7 Scammers know more about you than you think.   Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.  Download for iOS →   Download for Android →  
malwarebytes.comSep 3, 2026extracted
UK's Online Safety Act has made 'absolutely no difference,' kids say
Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "has made absolutely no difference" to their ability to access harmful content online. More than a year after the OSA's key child protection duties took effect, de Souza told MPs and peers that young people had little understanding of the legislation or how it was intended to change their online experiences. De Souza made the comments during the opening evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and impact. Central to de Souza's criticism was the legislation's focus on moderating harmful content rather than addressing potentially harmful platform design features. UK politicians had pushed for controls covering such features, either through the OSA or separate legislation, but none has materialized. De Souza said she was "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate. She contrasted that with the US, where legal pressure recently pushed Meta toward significant child safety concessions. Concerns about addictive platform design are not new, but they have returned to prominence following Meta's proposed $18 billion settlement in a US child safety case. Without admitting wrongdoing, Zuckercorp would under the proposed settlement introduce two-hour daily limits for users under 18 on Facebook and Instagram, prompts intended to discourage endless scrolling, and measures addressing use during school hours and at night. The proposal would also let children opt out of algorithmically ranked feeds, directly addressing concerns raised by de Souza and other UK lawmakers. Discussing the proposed Meta settlement, de Souza said the OSA had "not been flexible enough" and had not "kept up with the time." She argued that Ofcom and lawmakers should seek results comparable to those achieved through the US legal system, even if that required the legislation to evolve. 'Furious' with Ofcom De Souza said she planned to exercise her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of the safety risk assessments submitted by technology companies. The commissioner said Ofcom had refused to share the assessments with her, despite her position as "the most senior safeguarding person in this country for children," and had indicated that it would resist disclosure even if she invoked those powers. "One thing I did want to ask this committee was for your assistance in this matter, because I am planning to use my powers," De Souza said. "If we cannot even see the risk assessments that may well have put these [safety] mechanisms into place, or may not have, how on earth can we judge the efficacy of it? "So I'll leave that one with you, but I'm pretty furious about that." The obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies. Asked whether compelling tech companies to complete risk assessments was enough to ensure meaningful change or whether further legislation was needed, the Children's Commissioner said "we need a few things," including for Ofcom to "use its teeth." Ofcom has materially upped its presence in the tech regulation landscape during the past year, stepping in on multiple occasions when needed. Perhaps most notably this was at the height of the Grok nudifying furore, but also its sprawling list of investigations into pornography companies allegedly violating age verification requirements. De Souza acknowledged all of this, and the fact that since the introduction of the latest US administration, UK politicians have not given the regulator the "air cover" needed to relentlessly pursue offenders. Nevertheless, she said Ofcom had failed to bare its teeth as forcefully as the current technology landscape demanded and accused it of reacting to harms rather than anticipating them. "If Ofcom is going to be the vehicle to protect our children… we need them to be getting ahead of the harms. And I don't think they have. "So when I talk around the country to children, what's worrying them are things around AI, things around the nudifying apps… there are new harms, and we need Ofcom to be getting ahead of those. I don't think they are." De Souza called on UK politicians "to be really strong and direct" in empowering Ofcom to pursue offending organizations. "But how effective do I think they've been? Not effective enough." The commissioner also criticized Ofcom's child safety codes under the OSA, which she said read more like technical documents for technology companies than protections designed for children. She also called on Ofcom to "use all their powers," impose "some big fines," and act before new harms become entrenched. The Register asked Ofcom to respond. A spokesperson said: "We work closely with the Children's Commissioner and share her objectives to ensure children are safe online. "In December, we published our analysis of risk assessments from the first year of the Online Safety Act being in force, and the improvements we expected to see from platforms. "Our action has resulted in material improvements being made to risk assessments, ensuring that tech companies must implement all measures necessary to address the risks identified on their sites and apps. "We are subject to laws that mean we're restricted in what information we can disclose relating to businesses." ®
theregister.comSep 3, 2026extracted
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported. Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming. "There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem," ThreatFabric said in its StreamRat analysis. ThreatFabric did not attribute the campaign to a named threat actor. Once Accessibility access is enabled, operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely. The campaign begins when the social-media lure directs an Android user to a specially crafted website. The site checks the visitor's operating system. It displays its download button to Android devices. The visitor can then download a file named app.apk. The victim launches the APK. The dropper asks to become the device's default Home application, which returns the victim to its interface whenever the Home button is pressed. Before fetching the final payload, the dropper requests permission to establish a VPN connection. Once approved, the VPN routes device traffic into a nonfunctional interface while excluding the dropper itself. The dropper's main page downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk. The dropper next asks for permission to install applications from unknown sources. After approval, it installs the payload through Android's package installation mechanism. StreamRat launches. The payload requests Accessibility access. After the user grants that permission, the malware connects to its command-and-control (C2) server. The VPN interface forwards no routed traffic, causing other applications to lose internet connectivity during installation. The dropper shuts down the VPN after the payload executes, allowing StreamRat to communicate with its C2 server. ThreatFabric assessed that the interruption may reduce online reputation and code-analysis checks. Google Play Protect retains offline detection for known potentially harmful applications, limiting the technique's effect on the service. For a visible screen capture, StreamRat invokes Android's MediaProjection application programming interface (API), which displays a consent dialog and is typically identified by a screen-sharing indicator. The malware can use Accessibility to interact with the consent dialog after the victim has granted that permission. A second mode uses the Accessibility takeScreenshot() method to capture the screen outside the MediaProjection indicator. ThreatFabric said StreamRat was also promoted through TikTok. The report's TikTok-specific public evidence consisted of landing-page code that can identify TikTok as the referring application. It supplied no TikTok ad record or reach figure. The same banners were likely displayed on Facebook and Instagram, while the primary Meta placement remained undetermined. Applicability is tied to the installation behavior and the requested permissions, as no Android version range was published. The company shared the following indicators of compromise (IoCs) - SHA-256 - e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c Package - io.base.one887 Application - StrεαmTV Pro SHA-256 - ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 Package - io.meat.hint Application - Sistema de vídeo C2 IP - 45.147.28[.]59 C2 IP - 193.32.2[.]245 The Meta campaign began on June 11, 2026. It ended on July 3, 2026. The campaign was identified in late July 2026. The findings were published on September 2, 2026. The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign. The dropper closely resembled the one used in that operation. "The droppers are hosted using GitHub releases, with different backup links and daily package updates," Cleafy said in its Mirax report.
thehackernews.comSep 2, 2026extracted
Your AI chats could be used in court
You might tell an AI chatbot secrets that you wouldn’t divulge to your closest friends. If you do, though, beware: They could end up as evidence in court. An article in the Washington Post this week highlighted several cases in which people had discussed sensitive information with AI systems like Claude and ChatGPT, only to have their conversations obtained by prosecutors or opposing lawyers. Lawyers can get access to your chatbot conversations from AI services like ChatGPT because they aren’t privileged in the same way that, say, a conversation with your lawyer or a doctor would be. Reporters at the paper found chatbot logs cited in 12 court cases in the past two years. They also found statistics from OpenAI that supported a rising trend in data disclosures. The company, which operates ChatGPT, disclosed the content of more than 80 user accounts in the last six months of 2025. That was more than four times as many as in the second half of 2024. Cases are piling up With people asking AI for all kinds of advice, it’s little wonder that lawyers are coming after that data too. Sometimes, it emerges because users consent to a search. The Washington Post mentions one university student who asked ChatGPT in a panic whether people might work out that he had damaged 17 cars in a campus parking lot. He then handed his phone over to police for a search. A teen suing big tech companies over social media addiction saw his own ChatGPT history drawn into discovery. Deleting your chats isn’t watertight protection either. In The New York Times’ copyright lawsuit against OpenAI over collecting its content for training data, a judge ordered the AI company to preserve chat logs, including ones that users had asked it to erase. OpenAI complained that users were being “forced to forgo the privacy protections OpenAI has painstakingly put in place.” The company had to keep that data even though it had agreed to delete it under the EU’s General Data Protection Regulation (GDPR) and California’s privacy laws. Incidents like these involve responses to legal requests, but AI companies don’t always wait for a subpoena. OpenAI’s policy allows its reviewers to refer conversations to law enforcement whenever they identify “an imminent and credible risk of harm to others.” The Washington Post reported an incident in which OpenAI contacted police after a ChatGPT user in Palm Beach County, Florida, repeatedly described plans to harm an ex-girlfriend. Technology companies have been handing over all kinds of data beyond AI chats to law enforcement and litigants for years. Google, Meta, and Apple shared details of 3.16 million US user accounts between 2014 and 2024, with substantial increases in the number of records shared annually during that period. Every time a new technology emerges, litigants will go after it for data. In 2019, police issued a subpoena for audio recordings from an Amazon Echo owned by a Florida man charged with murdering his girlfriend. What to do We’d all like to think that true friends will carry our secrets to the grave. But AI is not your friend. Or your doctor, or your lawyer. Treat all chats as records that could potentially be disclosed in a legal case. They might feel like informal conversations, but you should assume that each one creates a written record, even if there’s a delete button. Be careful about what you share. If the topic is one you’d normally raise only with a doctor or a lawyer, then raise it with a doctor or a lawyer, not AI. Communications with lawyers may be protected by attorney-client privilege, while medical information is subject to confidentiality and privacy protections. Chatbot conversations aren’t. Finally, be cautious beyond AI. Everything from ill-advised social media posts to private messages might also find its way into police hands. In 2022, for example, Facebook handed over private messages between a mother and daughter to police investigating an illegal abortion case. So think twice before posting anything sensitive. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by  downloading Malwarebytes today .
malwarebytes.comSep 2, 2026extracted
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Healthcare facilities operator Nutex says patient, employee data stolen in August incident Hackers stole patient and employee data from healthcare giant Nutex during a cyberattack announced last week, the company said in regulatory filings on Monday. In an 8-K filing with the Securities and Exchange Commission (SEC), Nutex said it is being extorted by cybercriminals who broke into the company’s servers and exfiltrated information related to patients, employees and external providers as well as confidential financial data. “The third party has threatened to post such information externally,” Nutex said, adding that it is still investigating how much data was taken and what impact it will have on the company. Nutex earned $427.2 million in the first half of 2026 through its operation of 27 hospital and outpatient facilities in 12 states. It also controls a physician network focused on primary care. The Houston-based company initially disclosed a cyberattack to the SEC on August 24, warning investors that it hired cybersecurity experts to help address the attack. Monday’s filing notes that after the initial disclosure, a class action complaint was filed in Texas “on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident.” Nutex said that it is “unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company’s business strategy, operations, financial condition, results of operations or the trading price of the Company’s common stock.” The 8-K filing did not specify the cybercrime group. Nutex did not respond to requests for comment. The Gentlemen ransomware gang took credit for the attack on Monday, adding Nutex to its leak site. The ransomware-as–service group has operated since September 2025 and experts said it was created by a disgruntled former affiliate of the Qilin ransomware operation. The gang has launched at least 350 attacks since emerging and experts believe the group is based in Russia because it prohibits members from attacking Commonwealth of Independent States (CIS) countries and its posts on cybercriminal forums are written in Russian. The group allows affiliates to conduct both ransomware attacks and data exfiltration-only incidents, offering to only take a 3% cut of all ransoms coming from the latter. The group recently caused alarm after it shut down the IT system of nonprofit medical system AnMed and took over the company’s Facebook. AnMed was forced to shutter dozens of its facilities for a number of days and later confirmed that the hackers stole patient information. In the second quarter of 2026, the group claimed 125 attacks on industrial organizations, the operational technology firm Dragos said — the third most among ransomware groups. Two weeks ago, experts at Gambit Security said they saw an affiliate of the group using Claude Code during intrusions into at least six organizations. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaSep 1, 2026extracted
Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance
Meta pagherà fino a 17,1 miliardi di dollari in dieci anni. Una cifra che, letta isolatamente, sembra raccontare una sconfitta colossale per Zuckerberg. Se però allarghiamo lo sguardo, osserviamo cosa ha ottenuto Meta e guardiamo persino alla reazione della Borsa, la storia potrebbe essere esattamente opposta: Meta ha vinto, mentre a perdere rischiamo di essere ancora una volta noi. Il procedimento che avrebbe dovuto stabilire fino a che punto Facebook e Instagram siano stati progettati consapevolmente per favorire un utilizzo compulsivo da parte di bambini e adolescenti non arriverà infatti a una sentenza di merito. Meta ha raggiunto un accordo con una coalizione bipartisan di 51 Attorney General statunitensi che prevede almeno 12,19 miliardi di dollari garantiti nell’arco di dieci anni, cifra che potrà arrivare a 17,1 miliardi qualora anche altri grandi operatori accettino accordi comparabili. In cambio, Meta non ammette responsabilità, chiude un contenzioso estremamente pericoloso e accetta una serie di modifiche alle proprie piattaforme destinate alla protezione dei minori. La cifra fa certamente impressione, ma bisogna leggerla nella sua reale dimensione economica. Diciassette miliardi distribuiti su dieci anni equivalgono, semplificando, a circa 1,7 miliardi di dollari l’anno. Rapportati al fatturato annuale di un gruppo delle dimensioni di Meta rappresentano un costo enorme per qualsiasi impresa normale, ma assolutamente assorbibile per una società che genera ricavi annuali nell’ordine delle centinaia di miliardi di dollari. Il mercato sembra aver compreso perfettamente questo passaggio, tanto che alla notizia dell’accordo il titolo Meta è arrivato a guadagnare circa il 4% nelle contrattazioni pre-market. Una società che dovrebbe avere appena subito una delle più importanti sconfitte della propria storia viene premiata dagli investitori. Forse, prima di parlare di vittoria delle autorità, dovremmo quindi chiederci chi abbia realmente vinto. Indice degli argomenti Il primo errore sarebbe considerare questa vicenda come una semplice maxi-sanzione, perché ciò che Meta ha ottenuto potrebbe valere molto più dei miliardi che dovrà versare nei prossimi dieci anni. Le accuse formulate dagli Stati erano pesanti e riguardavano la progettazione di funzionalità capaci di incentivare un utilizzo compulsivo di Facebook e Instagram da parte dei più giovani, la consapevolezza dei potenziali effetti di questi meccanismi e, secondo le contestazioni, anche la raccolta illegale di dati relativi a bambini sotto i tredici anni. Una decisione giudiziaria nel merito avrebbe potuto produrre conseguenze enormemente più profonde di un accordo economico, perché avrebbe contribuito a stabilire un precedente sulla responsabilità delle piattaforme rispetto alla progettazione dei propri sistemi di engagement. Quel pronunciamento non ci sarà. Meta paga, modifica alcuni meccanismi delle proprie piattaforme e chiude il procedimento senza ammettere responsabilità. Dal punto di vista industriale è difficile considerare questo risultato una sconfitta, soprattutto osservando la reazione degli investitori. Il vero problema, tuttavia, riguarda ciò che accadrà adesso. Le misure previste dall’accordo sono apparentemente significative. Per gli utenti identificati come minori di diciotto anni è previsto, tra le altre cose, un limite predefinito di due ore giornaliere complessive su Facebook e Instagram, modificabile dal genitore, mentre tra mezzanotte e le sei del mattino l’accesso sarà bloccato di default. Sono previste inoltre limitazioni alle notifiche durante la notte e l’orario scolastico, insieme alla modifica o alla rimozione di alcune dinamiche legate all’engagement e di determinate funzionalità considerate potenzialmente dannose per gli utenti più giovani. Tutto questo, però, poggia su un prerequisito tecnologico tutt’altro che banale: l’age assurance, cioè la capacità di determinare con un livello sufficientemente affidabile se dietro un account si trovi effettivamente un adulto oppure un minorenne. Chiedere semplicemente all’utente quanti anni abbia non è evidentemente una soluzione. Un tredicenne che vuole accedere a un servizio riservato ai maggiorenni può dichiarare una data di nascita differente in pochi secondi, rendendo inefficace qualsiasi politica costruita esclusivamente sull’autodichiarazione. La sicurezza dell’intero modello dipenderà quindi da come riusciremo a stabilire l’età reale o sufficientemente probabile dell’utente. Qui cominciano i problemi. Più vogliamo essere certi dell’età di una persona, maggiore sarà la quantità o la qualità delle informazioni che dovremo raccogliere, elaborare oppure inferire su quella persona. Potremmo utilizzare documenti d’identità, sistemi terzi di verifica, informazioni provenienti dal dispositivo, tecniche di stima dell’età attraverso immagini o caratteristiche biometriche, oppure segnali comportamentali e informazioni già associate all’account per collocare statisticamente l’utente all’interno di una determinata fascia d’età. Esiste anche la possibilità di spostare questa funzione verso altri soggetti tecnologici, affidandola al sistema operativo, agli app store oppure a specifici identity provider. Ognuna di queste soluzioni genera un diverso modello di rischio e, soprattutto, modifica profondamente la quantità di informazioni personali necessarie per utilizzare un servizio online. La questione, quindi, non consiste soltanto nel capire come impedire a un quattordicenne di dichiarare di avere diciotto anni. Dovremmo prima stabilire quali informazioni siamo disposti a trattare su milioni, se non miliardi, di persone per determinare che quel quattordicenne abbia davvero quattordici anni. La differenza è sostanziale. Il framework descritto dalle autorità statunitensi contiene almeno un principio importante: il sistema di age assurance non dovrebbe obbligare gli utenti a fornire documenti governativi o altre informazioni sensibili. Dal punto di vista della privacy by design è certamente una buona impostazione, ma non elimina il problema architetturale. Semplicemente lo sposta. Se rinunciamo a un’identità forte, dobbiamo infatti utilizzare segnali alternativi sufficientemente affidabili da permettere una stima dell’età. Diventa allora necessario capire quali siano questi segnali, quale accuratezza possano garantire, quanti falsi positivi e falsi negativi producano, per quanto tempo vengano conservati e soprattutto se possano essere utilizzati anche per finalità differenti rispetto alla semplice verifica dell’età. Un dato raccolto per proteggere un adolescente potrebbe, almeno tecnicamente, diventare domani un ulteriore elemento di profilazione. Questo è il punto sul quale cyber security e protezione dei dati dovrebbero incontrarsi prima che l’age assurance venga implementata su scala globale. Esistono almeno due modelli profondamente differenti. Nel primo è la piattaforma social a verificare o stimare direttamente l’età dell’utente. Meta avrebbe quindi accesso ai dati o ai segnali necessari per stabilire se dietro un determinato account si trovi probabilmente un bambino, un adolescente oppure un adulto. Nel secondo modello l’attestazione avviene a monte attraverso un soggetto differente, che potrebbe essere il sistema operativo, l’app store, un identity provider oppure un servizio specializzato. Alla piattaforma dovrebbe arrivare soltanto l’informazione strettamente necessaria, ad esempio che l’utente abbia superato una determinata soglia di età, senza trasferire data di nascita, documento, nome, cognome o ulteriori attributi personali. Dal punto di vista della data minimization questa seconda strada appare decisamente più interessante, ma apre immediatamente un’altra questione: chi diventerà il custode della nostra età digitale? Apple e Google, controllando rispettivamente ecosistemi, sistemi operativi e app store utilizzati da miliardi di persone, potrebbero assumere un ruolo determinante. La verifica potrebbe diventare tecnicamente più semplice per le singole piattaforme, ma concentrerebbe un’altra informazione identitaria nelle mani dei grandi gatekeeper tecnologici. Il problema non scompare cambiando soggetto. Cambia soltanto il luogo nel quale decidiamo di concentrare il rischio. La direzione tecnicamente più interessante dovrebbe essere quella di costruire sistemi capaci di attestare un requisito senza necessariamente rivelare l’identità completa dell’utente. Una piattaforma che deve applicare determinate restrizioni a chi ha meno di diciotto anni non ha necessariamente bisogno di conoscere la data di nascita, il numero di un documento o altre informazioni identificative. Ha bisogno di sapere se quella persona appartenga oppure no alla fascia soggetta alle restrizioni. Il principio dovrebbe quindi essere quello di dimostrare il requisito senza consegnare l’identità, applicando realmente i concetti di privacy by design, minimizzazione del dato e separazione delle responsabilità. Una soluzione di questo tipo ridurrebbe anche l’impatto di un’eventuale compromissione, perché il problema dell’identificazione dell’età non riguarda soltanto la privacy. Riguarda direttamente la cyber security. Ogni volta che costruiamo un sistema capace di classificare sistematicamente milioni di utenti come bambini, adolescenti o adulti stiamo creando un nuovo patrimonio informativo. Quel patrimonio diventa inevitabilmente un asset e ogni nuovo asset informativo introduce una superficie di attacco. Data breach, abuso interno, correlazione con altri dataset, profilazione, function creep e utilizzi futuri originariamente non previsti devono essere considerati nella progettazione del sistema, non quando il sistema è ormai operativo. Il paradosso sarebbe evidente: potremmo finire per raccogliere ulteriori informazioni sui minori proprio nel tentativo di proteggerne la privacy e la sicurezza, aumentando contemporaneamente la quantità di informazioni disponibili sugli adulti perché, per distinguere gli uni dagli altri, il sistema dovrà inevitabilmente classificare entrambi. Esiste infine un equivoco ancora più pericoloso, perché conoscere l’età di chi utilizza uno smartphone non significa aver risolto il problema della sicurezza dei minori online. Significa esclusivamente aver ottenuto l’informazione necessaria per applicare determinate policy. La protezione viene dopo e dipende dal design della piattaforma, dagli algoritmi di raccomandazione, dalle modalità con cui viene misurato e incentivato l’engagement, dalla moderazione, dalle interazioni consentite, dalla pubblicità, dalla profilazione e dalla capacità di individuare e contrastare comportamenti predatori. L’age assurance è quindi un controllo abilitante, non può trasformarsi nell’alibi tecnologico attraverso il quale consideriamo risolto un problema enormemente più complesso. Diciassette miliardi di dollari sono una cifra perfetta per un titolo di giornale, ma raccontano soltanto una parte della storia. Distribuiti su dieci anni significano circa 1,7 miliardi l’anno, una cifra che per Meta rappresenta un costo industrialmente assorbibile se rapportato ai ricavi annuali del gruppo. Contemporaneamente l’azienda evita che uno dei procedimenti più importanti sulla responsabilità delle piattaforme social arrivi a una decisione di merito, non ammette responsabilità e vede addirittura il proprio titolo guadagnare circa il 4% nelle contrattazioni successive alla notizia dell’accordo. Difficile trovare i segni di una disfatta. Meta pagherà, cambierà alcune regole e costruirà sistemi più sofisticati per riconoscere i minorenni, mentre noi dovremo affrontare la questione che probabilmente avrà conseguenze molto più durature dei 17 miliardi: quale infrastruttura tecnologica utilizzeremo per distinguere un adulto da un bambino su Internet e, soprattutto, chi avrà il diritto di effettuare quella distinzione? Meta, Apple, Google, un identity provider, lo Stato oppure un soggetto indipendente? Stiamo cercando di risolvere un problema nato anche dalla capacità delle piattaforme digitali di conoscere, classificare e profilare sempre meglio gli utenti chiedendo alla tecnologia di conoscerli ancora meglio. Questo è il vero paradosso. Se sbagliamo architettura, tra qualche anno potremmo scoprire di aver tentato di proteggere i minori costruendo nel frattempo una gigantesca infrastruttura per la classificazione dell’identità digitale di tutti. A quel punto i 17 miliardi saranno stati probabilmente la parte meno importante della storia, mentre quella che oggi viene raccontata come una storica sconfitta di Meta potrebbe rivelarsi, ancora una volta, una sua vittoria. La sconfitta sarebbe la nostra.
cybersecurity360.itSep 1, 2026extracted
Ionos e il commercio elettronico per le PMI: come l’integrazione di IA e sicurezza Cloud trasforma la creazione dei negozi online
L’offerta di Ionos sugli e-commerce per le PMI parte da 1 euro al mese per sei mesi, IVA esclusa, con uno sconto del 97% sul prezzo indicato di 32 euro. La proposta di Ionos consente di creare un negozio online con strumenti di intelligenza artificiale, gestione delle vendite e marketing integrato. Sono inclusi, inoltre, dominio per il primo anno, casella e-mail da 12 GB e assistenza 24/7 in italiano. La soluzione viene proposta da Ionos nel mercato europeo dell’hosting, con dati gestiti nei propri data center secondo standard conformi al GDPR. Indice degli argomenti Il pacchetto Plus di Ionos è pensato per negozi che necessitano di una dotazione superiore rispetto al piano Starter. Il limite arriva a 5.000 articoli, mentre i prodotti digitali possono raggiungere 1 GB ciascuno. Il negozio può integrare metodi di pagamento e spedizione, oltre alle vendite attraverso Facebook e Instagram. Sono disponibili anche strumenti pubblicitari per TikTok, Google Ads, Google Ads Remarketing e Google Shopping. La gestione passa anche dall’app dedicata. SiteAnalytics permette di monitorare le attività del sito, mentre marketingRadar offre una funzione di intelligenza competitiva. L’IA interviene nella configurazione iniziale e nella creazione dei contenuti. Il pacchetto include un generatore di testi IA per supportare la realizzazione delle descrizioni. La piattaforma consente inoltre di partire da centinaia di template oppure generare il sito attraverso l’IA. L’obiettivo operativo è arrivare alla pubblicazione in poche ore o, in base al numero di prodotti, entro un giorno. Sul fronte infrastrutturale, Ionos offre data center moderni con dati protetti secondo il GDPR. I dati vengono trattati nel rispetto delle normative europee sulla protezione dei dati. L’offerta comprende anche assistenza clienti 24 ore su 24, sette giorni su sette, tramite e-mail, chat o telefono. È inoltre previsto un consulente personale, disponibile dal lunedì al venerdì negli orari d’ufficio. La proposta prevede una garanzia di rimborso di 30 giorni. Il prezzo promozionale del piano Plus è pari a 1 euro al mese per sei mesi, contro 32 euro al mese indicati come prezzo di riferimento. Il costo promozionale complessivo dei primi sei mesi ammonta quindi a 6 euro, IVA esclusa, contro 192 euro al prezzo indicato. Per E-commerce Plus la differenza tra prezzo indicato e prezzo promozionale nei primi sei mesi è di 186 euro, IVA esclusa.
cybersecurity360.itSep 1, 2026extracted
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept things moving. Different attacks, same useful mistake: something familiar was trusted without a second look. Here is the week... ⚡ Threat of the Week U.S. Disrupts Chinese Proxy Network Enabling Cyber Espionage — The U.S. Federal Bureau of Investigation (FBI) disrupted infrastructure associated with a technical quartermaster who sold reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. The QTYF group is said to have created and operated the QScan and QTRouter frameworks, which have been used to target U.S. critical infrastructure networks. It's employed by the China-based Nanjing Xinjiuwei Network Technology Company. Stop Scrambling, Start Governing: How IT Can Get a Grip on AI Spend Spiking AI bills have left IT teams scrambling. Leadership wants to know how much is being spent on AI, but getting an answer means checking five dashboards for data that’s stale by the time you read it. Read 1Password’s blog to learn how IT can manage AI spend across vendors, models, and teams. Learn More ➝ 🔔 Top News OpenAI Says Reward Hacking Drove AI Agents to Breach Hugging Face — OpenAI revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident took place during cybersecurity evaluations of several OpenAI models, and it was mainly fueled by what it described as a "highly capable, internal-only research model" comparable in scale to GPT‑5.6 Sol. "The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks – they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems," it said. TerminalFix Uses Fake Cloudflare CAPTCHAs to Drop Reverse Tunnel Implant — A new ClickFix variant, dubbed TerminalFix, aims to trick users into running a malicious command in Windows Terminal or PowerShell instead of directing them to the Windows Run dialog. The campaign, targeting organizations across multiple sectors, leverages compromised websites as a starting point to serve fake Cloudflare CAPTCHA verifications that prompt unsuspecting site visitors to copy and execute a malicious PowerShell command. The attack chain, according to Microsoft, is a sophisticated multi-stage process that leverages DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a bespoke custom reverse-tunnel implant that grants the attacker persistent, network-level proxy access through the infected machine. PaperCut Flaws Under Attack — Threat actors are chaining together two new security flaws in PaperCut NG and MF to execute arbitrary code on susceptible instances. "CVE-2026-81578 allows you to bypass authentication, and from there, you can edit a configuration file to exploit CVE-2026-82078 and gain Remote Code Execution," Jake Knott, head of threat intelligence at watchTowr, told The Hacker News. Huntress said it observed limited exploitation on two customer environments, with the attackers executing Base64-encoded commands on the targeted server as part of post-exploitation activity to determine user account and operating system using a chained command "whoami & ver." China-Made ZBT Routers Ship with 2 Backdoors — A firmware analysis of ZBT Deep Orange 3G/4G/LTE Router uncovered two new backdoors called SPEAKINGSTONE (CVE-2026-74233, CVSS score: 9.3) and DARKLANTERN (CVE-2026-74232, CVSS score: 9.3). The development came after at least 21 firmware images from the Chinese company were found to contain another backdoor called ENDLESSDOORS (CVE-2026-66747, CVSS score: 9.3) that's designed to start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. The two new backdoors predate ENDLESSDOORS. "SPEAKINGSTONE, like ENDLESSDOORS, is a phone-home implant that connects back to ZBT's cloud infrastructure and accepts remote commands," VulnCheck said. "DARKLANTERN is a backdoor that listens on the WAN and executes arbitrary commands. No authentication required. Both are written in Nim. Both communicate over UDP. Both are launched by the same binary, a connectivity watchdog called inetdetect." Fire Ant Targets Trusted Infrastructure in 2026 — The China-linked threat actor known as Fire Ant (aka UNC3886) has continued to remain active in 2026, going beyond hypervisors to target trusted infrastructure, including routers (including Cisco IOS XR routers), TACACS servers, authentication systems, and Linux management hosts to maintain covert access, collect credentials and traffic, and reach connected high-value environments. "The compromise impacted both the direct and third-party environments," Sygnia said. "Its trusted infrastructure relationships created potential reachability into connected external environments, including high-value networks and critical infrastructure. Fire Ant appeared to use this trusted position to explore access paths beyond the initially compromised environment." Compromised routers were used for covert connectivity, traffic collection, command-output manipulation, and suppression of logging. In addition, the threat actor used deployed long-lived implants across Linux management infrastructure, including Medusa rootkit-related components, custom SSH backdoors, Zabbix-masquerading malware (aka BridgeAgent) that acts as a pathway for actor-controlled access into connected environments, and packet-triggered backdoors. Another tool in Fire Ant's arsenal is TacTap, which is used for TACACS credential collection. "The actor also manipulated the evidence sources defenders depend on," Sygnia added. "It suppressed router logging, altered command output, captured administrative credentials, tampered with host logs, and deployed multiple persistent backdoors." ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — From CVE-2025-30237 through CVE-2025-30241, CVE-2025-15628, CVE-2026-9254, CVE-2026-16348, CVE-2026-78541 (TP-Link), CVE-2026-17106 aka CopyEscape (Docker), CVE-2026-70426 (Jenkins), CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, CVE-2026-15920 (Django), CVE-2026-19598 (Pods), CVE-2026-19874 (Konami Metal Gear Online 3), CVE-2026-75149, CVE-2026-67618 (Marimo), CVE-2026-77775, CVE-2026-77776 (Headroom LLM Proxy), CVE-2026-0251 (Palo Alto Networks GlobalProtect App), CVE-2026-59568, CVE-2026-59567, CVE-2026-59565 (Zscaler Client Connector), CVE-2026-69251, CVE-2026-73601, CVE-2026-69253, CVE-2026-69256, CVE-2026-73602, CVE-2026-69259, CVE-2026-69264, CVE-2026-73484, CVE-2026-69255, CVE-2026-70477, CVE-2026-73485, CVE-2026-73486, CVE-2026-73487, CVE-2026-70470, CVE-2026-69254 (Flowise), CVE-2026-19912, CVE-2026-19913 (Kaltura HTML5 Player Library), CVE-2026-79282, CVE-2026-79290, CVE-2026-79054, CVE-2026-79121, CVE-2026-79224, CVE-2026-79052, CVE-2026-79150, CVE-2026-78935, CVE-2026-79012, CVE-2026-79200 (Google Chrome), CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 (Ubiquiti UniFi), CVE-2026-18431 (Avada WordPress theme), CVE-2026-7791 (Amazon Skylight Workspace Config Service), CVE-2026-73554 (DoltHub), CVE-2026-19516 (Grafana MCP), CVE-2026-75604, GHSA-2xp9-vwfh-vxw4 (Next.js), CVE-2026-65643 (cPanel and WebHost Manager), CVE-2026-76639, CVE-2026-76640 (Unitree G1 EDU), CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 (ServiceNow AI Platform). 🎥 Cybersecurity Webinars AI Can Build Attack Paths in Minutes. Is Your SOC Ready? → AI can now discover zero-days, generate working exploits, and chain full attack paths, often within minutes of disclosure. Learn how to assess your AI threat readiness and build the visibility, context, and response speed needed to keep pace. AI Finds Flaws Faster. Your Exposure Answers Can’t Take Days → AI is speeding up vulnerability discovery, but the answer that matters is still slow: Are we exposed? See how Tines unified SBOM, application, cloud, and vulnerability data into one view to assess exposure faster and execute human-reviewed response playbooks at machine speed. 📰 Around the Cyber World Play Ransomware Encryption — The closed ransomware group known as Play (aka PlayCrypt) has been found to employ a double extortion model, encrypting systems after exfiltrating data and threatening to publish stolen data on their Tor-hosted data leak site if ransom is not paid. In one incident observed in early 2026, the threat actor deployed SystemBC after gaining initial access, followed by reconnaissance, lateral movement, data exfiltration, and abusing SentinelOne's own legitimate removal tool to uninstall the product. "The threat actor gained initial access via a compromised SonicWall VPN, consistent with the group's well-documented pattern of exploiting external remote services," GuidePoint Security said. "What makes this case particularly instructive for defenders is the combination of three specific behaviors: Domain-wide tool staging via the SYSVOL share rather than per-host delivery, EDR removal using the victim's own SentinelOne uninstallation utility rather than a kernel-level driver exploit, and the recovery of a crash dump from a host where the encryptor failed to complete, an artifact that provides a rare forensic window into the encryption execution itself." Email Bombing and Quick Assist for Ransomware Deployment — ZeroBEC disclosed details of an email bombing campaign targeting at least 10 users inside an organization, causing them to receive about 3,000 messages per day. "The messages were not a conventional phishing blast. Many were genuine verification, registration, deployment, and inquiry confirmations generated after the victims' email addresses were submitted to unrelated public platforms," the email security company said. About a day and a half after the email flooding, some of the users were contacted via Microsoft Teams by attackers masquerading as IT help desk personnel to help them tackle the problem. One of the employees, who was a local administrator, granted Microsoft Quick Assist access, enabling the attackers to deploy Xray-core, a reverse proxy tool, and expand their access. "The credential-theft step was woven directly into social engineering," ZeroBEC said. "The attacker mimicked the installation of a Windows security update and launched a local credential prompt from the compromised endpoint. The victim, who was still listening to the person he believed was IT, entered domain credentials into that prompt. The tooling validated and captured the credentials and then uploaded the resulting credential/configuration artifacts to an external Microsoft Dev Tunnel." Through the reverse tunnel, the threat actor conducted domain reconnaissance and attempted NTLM relay against certificate enrollment, all hallmarks of pre-ransomware deployment. It's worth noting the modus operandi shares overlaps with that of Aurora ransomware. ValleyRAT Delivered via Rogue Installer — A malicious installer disguised as adware has been observed deploying a modified version of the Chinese desktop wallpaper management tool, QN Wallpaper, which then performs DLL sideloading to establish persistence on Windows systems by dropping a file to the Startup folder and ultimately launching ValleyRAT, a backdoor linked to a threat actor known as Silver Fox. The malware, besides taking steps to protect its process, can collect system information, reboot/shut down the computer, take screenshots, wipe logs, update command-and-control (C2) addresses, download additional modules, and send keylogger logs along with clipboard contents. Per Kaspersky telemetry, ValleyRAT and its related components have been detected more than 100,000 times, with more than 1500 unique users affected, mainly in China and India. Brazil Fines ByteDance $29.81M for Privacy Violation — Brazil's data protection authority, ANPD, fined TikTok's owner ByteDance 153.8 million reais ($29.81 million) for allegedly violating the country's General Data Protection Law. ANPD said that the local unit of China's ByteDance had processed personal data of teenagers aged 13 to 18 without a valid legal basis. The regulator estimated that TikTok may have processed the data of at least 8 million children during the review period. DeepMind Debuts Double-Blind AI Evaluations — Google's DeepMind division launched a pilot of double-blind AI evaluations with an aim to keep external evaluations in a cryptographic "box" to stop benchmark contamination and protect intellectual property. To that end, Google said it's partnering with the Singapore AI Safety Institute, OpenMined, AVERI, and MLCommons, to test a Gemini Flash Lite model against confidential benchmarks in a privacy-preserving environment to increase evaluation integrity. "By using Confidential Space within Google Cloud’s Confidential Computing portfolio, we can cryptographically verify that both the external evaluation data and the proprietary model remain private to their respective owners," DeepMind said. "The evaluator cannot see the Gemini model weights, and Google cannot see the evaluator’s test prompts." 34 Malware Families Targeting Banking Apps — Zimperium found 34 mobile malware families actively targeting more than 1,243 mobile banking and fintech apps across 90 countries globally. "The concentration of targeted applications across EMEA reflects where threat actors anticipate the highest return on investment, focusing heavily on the region's major financial centers," it said. Some of the active malware families in the EMEA region are TsarBot, CopyBara, HOOK, Nexus, Flubot, Eventbot, and MaliBot. Fake KYC Apps Target Indian Customers to Deliver Ghost Penal — A new malware-as-a-service (MaaS) operation on Telegram, dubbed Ghost Penal, is selling ready-made Android banking trojan kits impersonating five major Indian banks. "The operation supplies a two-stage dropper protected by a custom native packer, a public cloud database that receives stolen UPI PINs and device data with no authentication required, and a downstream channel that relays intercepted one-time passwords for immediate fraudulent use," iZOOlogic said. The toolkit costs $25 for a five-credit pack and $400 for a three-month unlimited plan. One of the droppers containing the malicious payload masquerades as a video-calling application, while requesting access to SMS and telephony features. "The payload’s real functionality, including SMS interception, WebView-based KYC phishing, and data exfiltration, is not present in a static scan of the installed application," the company added. "It is protected by a native library, internally named libdpt.so, that decrypts a hidden code section in memory using RC4, forks the process before executing that code as an anti-debugging measure, installs hooks on libc and on the ART runtime’s class loader, and splices a second, hidden DEX archive into the application’s running ClassLoader. The same mechanism is then used in reverse to remove the trace of that injection." Bauman University Leak Exposes Russia's Military Cyber Training Pipeline — Leaked Bauman University records have revealed a long-running program that trained about 250 career and reserve students for special intelligence, operational information-technical effects, and information-technology protection under Department No. 4. "The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities," DomainTools said. "Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers." Department No. 4 is assessed to be tied to the GRU, with identified graduates assigned to military units associated with APT28 and Sandworm. Pentagon's Anthropic Blacklisting Ruled Illegal — A U.S. judge blocked Anthropic's designation by the Pentagon as a supply chain risk earlier this year. "Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless," District Judge Rita Lin said. "The empty invocation of national security is not a blank check to punish and retaliate against government critics." Anthropic said it welcomed the ruling and it remained "focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology." State of AI-Enabled Malware in August 2026 — Palo Alto Networks Unit 42's analysis of 405 malware samples that integrate AI in some capacity has found that only 12 of them reached a production environment, with about 97% existing only in sandboxes and on VirusTotal in the form of proof-of-concept and research code, security validating and testing, and AI-themed brand abuse. Among those that were detected in customer endpoints were FunkSec ransomware, a trojanized AI application called Recipe Lister, Oyster, Rhadamanthys Stealer, and a COM hijacking DLL. "For defenders, the practical takeaway is straightforward. Existing behavioral detection, cloud-based sandboxing and endpoint analytics catch these threats using the same mechanisms that stop conventional malware," it said. "The AI component does not evade detection. It changes how the code is authored, not how it executes." Rogue Pornographic Android Apps Lead to Financial Fraud — The Indian Cyber Crime Coordination Center (I4C) warned that malicious Android applications masquerading as pornography apps under the names Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa are being used to disseminate a banking trojan capable of carrying out financial fraud. These bogus apps are circulated through Facebook and Instagram ads and instruct victims to sideload the APK file. "After installation, the app requests permissions that allow it to install additional applications and, by abusing accessibility permission, take control of the users' device, which may result in financial fraud," I4C said. "Some apps also install a VPN, which may be used to route internet traffic pertaining to malicious/criminal activity. The app may prevent users from uninstalling it through the device settings." Details about the KYSS malware were published by security researcher Rudra Ponkshe in July 2026, describing it as a trojan designed to perform overlay attacks against 19 targets across Japan and Latin America, as well as abuse Android's accessibility services to grant itself extensive permissions, exfiltrate photos and contacts, and issue commands for subsequent execution. Conclusion The useful lesson is not that every attack became smarter. It is that more of them arrived through things already trusted: shipped devices, familiar prompts, support tools, valid access, and systems meant to protect the network. That changes the question. “Is it working?” is no longer enough. Ask what else it can do, who else can reach it, and whether the evidence it produces can be trusted. Quiet systems deserve a second look.
thehackernews.comAug 31, 2026extracted
A week in security (August 24 – August 30)
Last week on Malwarebytes Labs: Protect your WhatsApp account with new passkey and 2FA upgrades The AI agent swarm that attacked Hugging Face is a warning for the future Flock wants privacy to meet surveillance halfway Fake listings can turn trusted platforms into scam springboards Fake Apple Pay charge brings the classic tech support scam to your phone New Instagram and Facebook rules set a default two-hour limit for teens Update Chrome before you browse again Popular school apps may be sharing student data with advertisers Beware of fake Indeed interview apps used to install spyware Grok fooled into stealing user chat, location data, and more GTA 6 leak hunt could expose data belonging to thousands of Discord users TikTok phishing: How to spot fake login and verification pages Fake GTA 6 Extended Look and demo sites deliver an infostealer Fake Microsoft security scans trick victims into uninstalling their antivirus What happens to your data when you die? (Lock and Code S07E17) AliExpress caught using silent audio to fingerprint visitors’ browsers ToxicPanda 2.0 can take over your Android phone and banking apps Tracking PavinLoader across ClickFix and fake download campaigns Stay safe! Scammers know more about you than you think.   Malwarebytes Mobile Security protects you from phishing , scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.  Download for iOS →   Download for Android →  
malwarebytes.comAug 31, 2026extracted
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures. Researchers say all 19 malicious modules uncovered in the campaign serve distinct purposes and are designed to be "highly extensible." The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024. Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware. According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically. One example is the "Enable Right Click & Copy — Smart Unlock + OCR" extension, which had a Chrome user base of at least 70,000 when it turned malicious. The number of installs on Edge was 10,000 at the time. Google caught the threat early and removed the extension from its add-ons marketplace, but at the time of Socket publishing its report, the Edge version remained available. Once installed, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every website visited, and injects malicious scripts into websites through hidden HTML elements. Socket observed malware modules with the following capabilities: Draining EVM, Solana, and Tron wallets by hijacking legitimate “Connect Wallet” and “Swap” buttons Replacing Ledger and Trezor websites with convincing seed-phrase phishing pages Stealing sessions, tokens, account data, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask Recording credentials and form entries across websites Harvesting Facebook and LinkedIn account information Exfiltrating browser history Displaying ClickFix-style fake browser updates that instruct victims to execute attacker-provided commands Socket warns that the malicious framework may have more modules and that as the malware evolves over time, new payloads are expected to be deployed. At the time of publishing, none of the malicious extensions are available in the Chrome Web Store. Socket's report provides the full list of extension IDs uncovered in the campaign along with the domains used for C2 communication. Users who had any of the extensions installed should assume that their credentials have been compromised and change their login passwords. Cryptocurrency holders potentially impacted by this campaign are recommended to move their assets to a newly created wallet as soon as possible. Update [August 30]: Article edited to include the full list of malicious extensions discovered by Socket. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 30, 2026extracted
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active since February 2024. Socket is tracking the activity under the name Superior. The modus operandi is relatively straightforward: the threat actor either acquires legitimate extensions with proper functionality or pushes a clean version that's devoid of any malware. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published. Of the identified extensions, 14 were created by the threat actor, while the remaining five were purchased from their previous owners. The complete list of extensions is below - Extensions bought by the threat actor koccklolohdacbfooifnpebakpbeipc - Enable Right Click & Copy — Smart Unlock + OCR fegckejpfnlmfgkfjpinlbgmeeijjkel - RapidLens - Google Lens for Screen Search & Images kdenlnncndfnhkognokgfpabgkgehodd - QuickLens - Search Screen with Google Lens jamminefolhgepgihbmcjjhgldbfcikp - Password Protect PDF inmkjedjdhgpknjogbjomhnbgdccckkg - Allow Copy - Select & Enable Right Click (Microsoft Edge) Extensions created and published by the threat actor - fcgdejjichpgfaaafflplhfijcnieopb - PixelCheck cfpnjdbpojpcongfaefcamjbaolpelcd - Creative Library - Ad Spy Tool aapdalkmclfaahehnmicbglkohkldhne - Website Traffic Checker: MirrorSphere SEO Stats dkdadldmiefjldmegbjbnhhfddnkhlhm - Site Signal - Website Traffic & SEO Checker fjmlhlkccegopebcllcmafahkmeejpph - SEO Pulse Pro - Website Traffic & SEO Analyzer iekoapohahgmogbagegmcgplbkikcgke - Private Crypto News Reader ahpnnnjbnfbhoikhohglpohnoocjcoco - Blockfolio: Address Monitor oeacadlaclegkkkdehjmiifnjhcekclj - Crypto Rates & Fiat Converter jmlgannjlbliikgcaieomgmcnfplglea - Crypto Alerter: Price Alarms & Volatility Warnings lhmcajhgadanidbopgaoobjlldegjmke - DeFi Pulse Tracker gfackggoapepdmnjnkblogdcjpgcjiak - Crypto Price Badge: Quick Glance hfijkbdkpidafdbeebnnkhfccildbcle - Multi-Chain Explorer cngchfbfgejllcbhmeadjhiebebiome - LedgerLook: Wallet Checker aodkjdeghbjiaienipfjkbpcikkacbcp - Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray It's worth highlighting that the "QuickLens - Search Screen with Google Lens" was previously flagged by both Annex Security and monxresearch-sec earlier this year, detailing its ability to push malware to downstream customers, inject arbitrary code, and harvest sensitive data. The latest findings from Socket suggest that the activity is broader in scope than previously thought and has been ongoing since February 2024. Some aspects of this campaign were documented by DomainTools Investigations in May 2025. At the time, the threat actor was observed creating fake websites masquerading as legitimate services, productivity tools, ad and media creation or analysis assistants, VPN services, cryptocurrency or banking utilities to trick users into installing malicious extensions from the Chrome Web Store. "The extensions typically have a dual functionality, in which they generally appear to function as intended, but also connect to malicious servers to send user data, receive commands, and execute arbitrary code," DomainTools Investigations said. The extension with the most potential impact is "Enable Right Click & Copy — Smart Unlock + OCR," which has a collective install base of 80,000 users across both Chrome and Edge browsers. Each of the extensions also supports the ability to establish contact with a command-and-control (C2) server and set up a persistent WebSocket connection. "Worth noting is that the loading framework supports rotation of the C2 endpoint based on instructions received from the initial C2 server and this behavior has been observed in the wild," Zanki explained. "That functionality enables threat actors to distribute victims to different groups and dedicated C2 infrastructure and to reduce the detection risk. Data exfiltration endpoint is also dynamically received from the C2 instructions enabling a per-victim exfiltration channel." As observed in the case of QuickLens, the malicious code embedded in the extensions strips Content Security Policy (CSP) headers from every page and facilitates the injection of JavaScript code modules on targeted websites using content scripts. A total of 16 modules have been identified. They span the following categories - Multi-chain wallet drainer Hardware-wallet seed-phrase harvester Cryptocurrency exchange and wallet account harvester Universal credential or form grabber Facebook and LinkedIn account stealers Browser history stealer ClickFix-style lure The ClickFix module injects a fake web browser update and employs operating system-specific instructions to get the user to copy and paste the malicious command. Exactly who is behind the campaign remains unknown. But the fact that they have been successfully operating for more than two years points to a "very capable threat actor." "The biggest risk for end-users is the operational technique in which the threat actor successfully acquires legitimate extensions and releases new versions empowered with malicious functionality," Zanki said. "That approach, combined with Chrome's default extension update settings, performs auto-updating to the latest version of extension, providing the threat actor with a powerful vector to maximize the impact and reach of the extension acquisition."
thehackernews.comAug 28, 2026extracted
Ataques sin interacción contra cuentas de WhatsApp en iPhone con iOS 16
Ataques sin interacción contra cuentas de WhatsApp en iPhone con iOS 16 28/08/2026 Vie, 28/08/2026 - 10:20 Durante mayo de 2026 se identificaron en Italia varios casos de cuentas de WhatsApp utilizadas sin autorización en dispositivos iPhone que ejecutaban distintas versiones de iOS 16. Los primeros casos fueron comunicados a la empresa italiana de informática forense Forenser durante varios días de ese mes, después de que usuarios detectaran que desde sus cuentas se habían enviado mensajes solicitando transferencias de dinero a contactos recientes. Las investigaciones forenses realizadas sobre estos dispositivos identificaron elementos comunes entre los incidentes, entre ellos la ausencia de dispositivos desconocidos en la sección «Dispositivos vinculados» y la inexistencia de una acción previa de emparejamiento por parte de las víctimas. Los casos analizados afectaron a diferentes modelos de iPhone, desde el iPhone 8 hasta el iPhone 14, todos ellos con alguna versión de iOS 16. Forenser relacionó los incidentes con una posible cadena formada por CVE-2025-43300, una vulnerabilidad de escritura fuera de límites en ImageIO de Apple, y CVE-2025-55177, una vulnerabilidad de autorización insuficiente en los mensajes de sincronización de dispositivos vinculados de WhatsApp. Esta última permitía que un usuario no relacionado provocara el procesamiento de contenido procedente de una URL arbitraria en el dispositivo objetivo. Ambas vulnerabilidades ya habían sido corregidas por Apple y WhatsApp durante 2025, aunque los dispositivos que permanecían en versiones vulnerables de iOS 16 podían seguir expuestos. En cuanto a las medidas adoptadas, WhatsApp había corregido CVE-2025-55177 en WhatsApp para iOS mediante la versión 2.25.21.73 y en WhatsApp Business para iOS y WhatsApp para Mac mediante la versión 2.25.21.78. Apple, por su parte, corrigió CVE-2025-43300, entre otras versiones, en iOS 16.7.12 y posteriormente en versiones más recientes de sus sistemas operativos. En los casos de 2025, WhatsApp también notificó a menos de 200 usuarios que consideraba potencialmente afectados y recomendó mantener actualizados tanto WhatsApp como el sistema operativo, mientras que Apple informó de que había recibido indicios de explotación de CVE-2025-43300 contra personas concretas. En el estado actual del incidente, la investigación publicada por Forenser continúa describiendo como hipótesis técnica la utilización conjunta de CVE-2025-43300 y CVE-2025-55177 para explicar los casos observados en dispositivos con iOS 16. La evidencia forense recopilada incluye eventos anómalos de «resync» en los registros de WhatsApp y errores relacionados con el procesamiento de imágenes, y Forenser señala que ha conseguido reproducir parte del escenario en un entorno controlado. No obstante, WhatsApp no ha publicado un comunicado específico que confirme que los nuevos casos de mayo de 2026 sean consecuencia de esta misma cadena de vulnerabilidades; por tanto, no puede atribuirse oficialmente a WhatsApp dicha explotación concreta más allá de la relación técnica planteada por la investigación forense.   Referencias 29/08/2025 WhatsApp / Meta WhatsApp Security Advisories 2025 – CVE-2025-55177 29/08/2025 NIST / NVD CVE-2025-55177 Detail 29/08/2025 INCIBE-CERT CVE-2025-55177 29/08/2025 TechCrunch WhatsApp fixes 'zero-click' bug used to hack Apple users with spyware 30/08/2025 The Hacker News WhatsApp Patches Zero-Click Exploit Targeting iOS and macOS Devices 31/08/2025 Tweakers WhatsApp fixt zeroday die gebruikt werd om iPhones te infecteren met malware 25/05/2026 Security Affairs Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning Etiquetas Apple Intrusión Suplantación Vulnerabilidad + WhatsApp -
incibe.esAug 28, 2026extracted
Australian cops cuff alleged TeamPCP masterminds
security Industry that built the problem offers to sell you the solution100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses SYSTEMS Nvidia and Cerebras are selling performance their customers will (probably) never seeTouting batch 1 token generation is a bit like boasting about the top speed of your car software Google forces Android apps to use memory more wisely as RAMpocalypse ragesNo one can afford RAM anymore, so we're requiring devs to mind memory usage personal tech HP has a solution to expensive AI tokens: Buy a more expensive PCRising cloud AI costs are pushing workloads onto pricier PCs – which just happen to be better for PC maker's margins SYSTEMS Meta's new MTIA 400 chip has a split personality: Training AI and serving adsFaster than Blackwell, but still no replacement for AMD or Nvidia ... yet Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career LibreOffice 26.8 is out – local first, and with no AIIt looks a bit clunky, but it does the job – and on your own computer Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is comingGRUB's up for furry new update AROS, the FOSS recreation of AmigaOS, comes to Raspberry PiPlus: new official Amiga-branded hardware is coming Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way
theregister.comAug 28, 2026extracted
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP , a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing. TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed  Shai-Hulud , which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen. Writing for Wired , journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers. “The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May . “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.” TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries. A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com. “TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote . “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.” In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM , an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies. In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub , after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware. MEET THE CYBERCATS Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals. “It is not a structured criminal crew with a single operator,” said Austin Larsen , a principal threat analyst with the Google Threat Intelligence Group . “It is a peer community of individually-skilled actors, with one clear center of gravity.” That center of gravity is George Prepakis , an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub . Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months. A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months. Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media. The Cybercats administrator listed at the top of the screenshot above — “ Boxturtle ” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle . This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group , Audi , Honda , Mercedes-Benz , Volvo and Toyota , as well as data allegedly taken from Snapchat and SportRadar . The data leak site for the extortion group or handle “xpl0itrs.” The Cybercats administrator “ SeesawSec ” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec , which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk , the data broker LexisNexis , and Avnet , a Fortune 500 distributor of electronic components. The data leak site of Fulcrum Security, a.k.a. Fulcrumsec. The Cybercats administrator “ @pcpcasper ” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia. At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning. The Cybercats member roster pictured above also features an administrator with the username “ T ,” which is short for the now-banned Twitter/X profile @pcpcats , the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia. By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off. WHO IS THE TEAMPCP LEADER? The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host , which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars. DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com. According to the cyber intelligence firm Intel 471 , Express registered on Breachforums using the email address [email protected] . Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa . On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency. The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP —  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025. Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign . This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.” BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.” The identity threat protection company SpyCloud finds [email protected] shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found. KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com , and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson . Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025. Searching on “ joshuathomson39 ” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben , his father Ian , and his mom Cindy. That Facebook profile also says Josh and his family are originally from Pietermaritzburg , in KwaZulu-Natal, South Africa, but currently living in Cottesloe , a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au , thomson.org.au , and thomsonfamily.net.au . Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa. Constella finds a [email protected] registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports [email protected] frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including [email protected] and [email protected] . According to Intel 471, [email protected] was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15 . On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to [email protected]. A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org. SpyCloud reports 10.141.230.15 was used by the email address [email protected] on Raidforums and [email protected] on Nulled, and that the same IP was used by the email addresses [email protected], [email protected], and [email protected]. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420 , YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says [email protected] was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen. Epieos reports that [email protected] is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis . I’m a Perth creative who occasionally books rooms when visiting family and for photography.” Epieos also finds [email protected] registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development. “I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.” The Upwork profile for Ruben Thomson in Cottesloe, Australia. Epieos further discovered [email protected] is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that [email protected] was used to register a forum account named ChristmasSnow). This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia. Business reviews in Western Australia left by the Google account sheepstealing at gmail.com. The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson. Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions , Tensor Industries , and another entity ironically named OPSEC Express . Recall that Express was BulkDMT’s nickname on Breachforums. Australian companies connected to Ruben Thomson. Image: abr.business.gov.au. It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice. There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne , a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3 , a nickname that has been flagged by multiple security firms as an alias used by TeamPCP. The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io. INTERVIEW WITH ELLIS In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis]. Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene. “One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.” Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.” “Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.” Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it. “I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.” Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested. “If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.” It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.” “What kind,” @kernelstub inquired. “Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand. Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends. Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer. An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT. The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today. Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories. “They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.” Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap. “You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.” According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences. “They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.” In a recent blog post , Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards. In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature. Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years. “They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.” Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.
krebsonsecurity.comAug 27, 2026extracted
New Instagram and Facebook rules set a default two-hour limit for teens
Meta decided that discretion was the better part of valor on Wednesday, agreeing to settle a landmark child safety case for up to $17 billion. The agreement would introduce a default two-hour daily limit for teens on Instagram and Facebook, overnight restrictions, and a range of other protections. It also brings the trial to an early end before Mark Zuckerberg, who was listed as a witness, could testify. The company reached the settlement with a bipartisan coalition of 51 state attorneys general, after four days of proceedings in a federal trial in Oakland. California, Colorado, Kentucky and New Jersey led the case, which they filed in 2023. It alleged that Meta broke state laws by designing addictive products for young users without warning them of the risks. It also accused the company of violating the federal Children’s Online Privacy Protection Act (COPPA) law, which protects the privacy of children under 13. Because violating these laws carries potentially hefty fees for each violation, Meta’s liability could reportedly have run to $1.4 trillion had it lost at trial. The states had proposed a penalty of $193 billion. By settling, Meta reduced that potential bill considerably. Meta denies the allegations, and we should point out the settlement does not constitute an admission of wrongdoing. What Meta will have to do in the US Under the agreement, Meta must introduce a default two-hour daily limit for Facebook and Instagram users under 18 in participating US states and territories that only a parent can lift. Meta must also block access between midnight and 6:00 am unless a parent intervenes. Most notifications will be silenced between 10:00 pm and 7:00 am, and during the school day from 8:00 am to 3:00 pm between August 15 and June 15. The social media giant must also hide likes and reaction counts from users under 18 by default. Teens will also be banned from applying filters that imitate cosmetic procedures, although ordinary makeup, skin-smoothing, fantasy, and parody effects are excluded. Teens can opt into a chronological feed populated by accounts they follow or have friended, rather than content selected by Meta’s recommendation algorithm. Meta must also provide its decision within six hours in at least 90% of English- and Spanish-language reports from teens about specified categories of potentially harmful content. An independent auditor will be checking all of this and reporting directly to a bipartisan committee of attorneys general. Public summaries of its findings will also be published. This is the piece of the agreement that most looks like ongoing regulation rather than a one-off payment. Payment and conditions Meta won’t pay all the money at once. It must pay more than $12 billion, mostly in installments over the next decade, with another $5 billion dependent on changes across the wider social media industry. Meta only has to make the conditional payments if Snap, YouTube, and TikTok adopt equivalent time limits, overnight restrictions, and age-assurance measures. Rival companies with annual profits above $10 billion must also face comparable payments to the states. If those conditions are met, Meta will move to a 60-minute daily limit on each platform, with a maximum of two hours across its platforms, and expand the overnight restrictions from midnight–6:00 am to 10:00 pm–7:00 am. Damning testimony in court A 2021 internal survey found that 51% of teen Instagram users said “yes” to having a bad or harmful experience on the app within the previous seven days , according to former Meta safety engineer Arturo Béjar, who testified at the trial. The same survey found the harmful content was taken down just 0.02% of the time. Béjar said he sent the findings to Zuckerberg but didn’t get a response, and testified that the company operated a “don’t ask, don’t tell” strategy toward the safety of children on its platforms. Other legal woes for Meta This lawsuit isn’t the first that Meta has dealt with out of court. In May it settled a case brought by a Kentucky school district that accused social media platforms of creating a mental health crisis in its schools. Snap, YouTube, and TikTok had already settled the case, which was seen as a test for a much larger group of lawsuits—what’s called a “bellwether case”. Meta has fared poorly in the cases that have reached a verdict. In March, Meta and Google lost another bellwether case in Los Angeles, brought by a 20-year-old user who accused it them of creating an addictive product that affected her mental health from an early age. Meta also lost a recent child safety case in New Mexico, resulting in almost $942 million in penalties after the judge accused it of creating “a public nuisance” with its platform design. This settlement doesn’t end Meta’s legal problems. There are roughly 3,000 addiction lawsuits against Meta, Google, TikTok, and Snap currently underway.  More than 1,000 school districts also have cases pending. And the law doesn’t seem to be on its side. In early August, the US Court of Appeals for the Ninth Circuit ruled that Section 230 offers “a defense against liability,” rather than immunity from being sued in the first place . Advice for parents right now In January, the American Academy of Pediatrics issued a policy statement arguing that parents shouldn’t have to govern their kids’ welfare in a digital world by relying on screen time limits alone. Tech companies and governments should focus on healthy platform design themselves, it added. This settlement seems to take a step toward that, although it took 51 attorneys general and a federal trial to get Meta there. Big tech companies have repeatedly shown that parents cannot rely on them to put children’s interests first. With this in mind, read the Malwarebytes research and guide to keeping your kids safe online. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by  downloading Malwarebytes today .
malwarebytes.comAug 27, 2026extracted
Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case
Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case In a bellwether case for U.S. privacy and kids’ online safety rules, social media giant Meta agreed Monday to pay $17 billion and implement a series of landmark reforms, settling accusations that it knew and hid findings that its Facebook and Instagram apps are addictive. The settlement, agreed to just days into a civil trial, requires the tech giant to drastically overhaul its approach to how kids use its service. The plaintiffs included nearly every U.S. state and territory. The lawsuit also alleged Meta flouted the federal Children’s Online Privacy Protection Act (COPPA), collecting data from kids 12 and under by relying on self-reported ages instead of facial recognition or other more rigorous age verification tools. The lawsuit, spearheaded by California, Colorado, Kentucky and New Jersey, is widely considered a landmark for testing how courts will view social media harms and children. “It is an unprecedentedly high number,” California Attorney General Rob Bonta said of the fine at a Wednesday press conference. “It’s the highest financial payment of its kind, way higher than opioids.” But Bonta said the large payout is nowhere near as important as the staggering range of reforms the attorney generals say Meta will implement. Meta has agreed to limit time on its apps to two hours per day for users under age 18; block youth from using the platforms between midnight and 6 a.m.; ban users under 18 from seeing “likes” or other reactions to their posts; and bar them from using cosmetic surgery image filters, according to Bonta. The settlement also requires Meta to offer young users the ability to have a “non-personalized” feed that is not shaped by an algorithm. Default blocks on notifications to users under 18 from 10 p.m. to 7 a.m. and during the school day also will be enforced, Bonta said. A tool for teens to report potentially harmful content will be offered and Meta will be required to respond to 90% of those reports in less than half a day. The tech giant also agreed to hire an independent auditor with "expansive access to information and resources" and the “right to communicate concerns” with the state attorneys general who brought the lawsuit. Finally, Meta will be barred from “making further false, misleading, or deceptive statements around its safety features,” according to a Bonta press release. “This settlement is social media's Big Tobacco moment,” said Jim Steyer, CEO of Common Sense Media, in a statement. “The message to the tech industry is clear: build child safety in, or courts and legislatures will make you.” Meta likely to decide to settle in the face of mounting lawsuits, recent losses in New Mexico and Los Angeles in similar cases and a recognition that the status quo is not sustainable in a culture where parents are increasingly angry about how tech is affecting their kids, according to James Speta, a professor of law focused on internet policy at Northwestern University School of Law. “These new restrictions and accountability mechanisms will likely change the experience on Instagram and Facebook, and they are designed to reduce engagement,” Spoto said. “There is no doubt that this is a big deal.” On Wednesday, Meta also settled with Texas for about $1 billion to resolve similar charges pursued by the state. Many other lawsuits from parents, users and school districts remain ongoing. It is unclear how Meta’s unprecedented settlement in today’s case will impact those cases. Meta’s final payment obligation will be determined by an unusual arrangement in which the total depends on how many other tech giants — Snap, TikTok, YouTube — accept fines. The social media giant called upon rival services, singling out TikTok and YouTube, to also work with state law enforcement to develop their own reforms. “Ensuring teens have a safe and productive experience on our platforms is an absolute imperative for Meta,” the blog post said. “While this is an important step, the fact is that teens move fluidly between dozens of apps a day.” “For meaningful progress to happen, we urge TikTok and YouTube to join us and state attorneys general in adopting this new standard, to ensure teens use social media in a healthy and responsible way.” Regardless of what other platforms do, Bonta hailed the agreement as revolutionary. "Meta has agreed to make massive transformations that will reduce the risk of harm from its platforms — and will do it within months," he said. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaAug 26, 2026extracted
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. The settlement, which is awaiting court approval, resolves a lawsuit filed in 2023 by California Attorney General Rob Bonta and a bipartisan coalition of state attorneys general. The lawsuit accused Meta of designing features that drove compulsive use among young users while misleading users, families, and the public about the risks of its platforms. The attorneys general also alleged that Meta illegally collected and used data belonging to children under 13, violating federal and state laws, including the Children's Online Privacy Protection Act (COPPA), California's False Advertising Law, and California's Unfair Competition Law. Under the agreement, Meta will introduce new restrictions for users under 18 on Facebook and Instagram, including a default two-hour daily usage limit that can only be turned off with parental permission. If YouTube and TikTok agree to similar terms, that limit would be reduced to one hour. Meta will also block teens from using its apps between midnight and 6 a.m. by default and mute most notifications between 10 p.m. and 7 a.m. and during school hours, which a parent can modify. Direct messages and some account security or safety alerts are excluded from some of these restrictions. Other requirements include hiding like and reaction counts from teenagers, blocking cosmetic surgery filters, providing an option for a non-personalized feed, strengthening parental supervision tools, and deploying additional age-verification technology to identify users under 18 and remove children under 13. An independent auditor will also oversee Meta's compliance with the agreement, while the company will be prohibited from making false or misleading claims about its safety features. Meta says the agreement includes approximately $18 billion in payments over ten years. Participating states are set to receive roughly $12.7 billion. Another $5.3 billion will only be released if YouTube and TikTok adopt similar changes, including one-hour daily limits, nighttime restrictions, and age-assurance measures, and each makes a matching payment. "The agreement is designed to drive industry-wide adoption, ensuring teens receive consistent protections across the apps they use most, like YouTube and TikTok. If industry peers adopt this new standard, certain provisions will be strengthened," announced Meta. Of this money, California expected to receive between $1.5 billion and $2.1 billion. "How a significant portion of the payment received by California will be spent will ultimately be decided by the Legislature and Governor, but in the proposed settlement it is earmarked for purposes related to the prevention or remediation of mental health or other harms to young Californians associated with social media use," explains the press release by Attorney General Bonta. Meta said it expects to incur approximately $10 billion in legal expenses related to the agreement in the third quarter of 2026 Most of the new protections must remain in place for ten years, and the agreement also establishes an independent research foundation focused on teen well-being and social media use. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 26, 2026extracted
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a self-described 'expert community' based in Israel," the company said. "What began as an investigation into AI-generated social media posts led us to a much broader influence operation, built around a website containing copied and misattributed academic work, a 'sovereignty' index that cast Russia in a favourable light, and efforts to disguise the operators' Russian origins." The campaign is assessed to have reached "relatively small audiences," with Telegram channels attracting more users and amassing about 10-20,000 followers each. The majority of the generated content was in English and the operators instructed ChatGPT to conceal any linguistic clues that could allude to their Russian provenance. The IBI brand is associated with a website ("ibi[.]institute") that was registered in February 2025. It claims to be a community of leading experts from across the world in matters of economics, politics, sociology and international relations. There is no evidence that articles published on the site were created using ChatGPT. However, many of them seem to have been copied from academic writings, in some cases with false attribution, while others were seemingly drafted by a Slavic speaker and then machine translated to English. What's more, OpenAI said the covert campaign is distinct from already documented Russia-linked influence operations, its notable aspect being the creation of a sovereignty index that was promoted by the so-called think tank to project Russia favorably and criticize Western countries. The website explains the Sovereignty Index, also called the Burke Index, is calculated by taking into account seven indicators that span account political, economic, technological, information, cultural, cognitive, and military sovereignty. "Each of the 7 areas of sovereignty is calculated using equalization coefficients based on a maximum score of 100 points, which in turn is formed from official national and global data sources and expert assessments," the website states. "The sum of 7 indices in the range of 100-700 forms the final Cumulative Sovereignty Index." The IBI website also includes reports on different countries and their sovereignty, as measured by the index. The U.S. leads the list with a score of 650.9, followed by China at 649.1, Switzerland at 610.7, and Russia at 601.4. The report on Russia includes the following assessment - In 2025, Russia is a state with a high level of sovereignty and record military and economic self-sufficiency, a strong scientific and cultural base, but with limited flexibility of the civilian economy and dependence on internal administrative capital. The main vectors of strengthening are demography, investments in high technologies and gradual liberalization in non-military science and innovation. The sovereignty profile indicates that by 2025 Russia has established a stable and high level of national sovereignty, from financial and military self-sufficiency to digital and cultural control over the internal environment. The country has become one of the three world powers with full digital and military nuclear sovereignty. Demographic aging, innovation constraints, and selective global integration remain key challenges, requiring a balance between closure and modernization. The activity extended beyond generating content about IBI, as one of the ChatGPT users used the tool to create a profile picture for a Telegram channel named "American Observer" and repeatedly asked for Russian-language summaries of the channel activity. "The significance of the operation lies less in the audience it reached, however, than in the infrastructure it had built," OpenAI said. "While the actors only used ChatGPT to produce isolated promotional posts, those posts pointed to an otherwise credible-appearing institution, complete with purported experts, republished academic work and a purported proprietary risk index." "This illustrates how influence actors can use AI as a supporting tool within a broader effort to manufacture authority, obscure the source of favored narratives, and establish assets that could be scaled over time. It also illustrates how their supporting use of AI can lead to the broader operation being exposed."
thehackernews.comAug 26, 2026extracted
Cybersicurezza, WhatsApp annuncia nuove funzioni per migliorare la tutela degli utenti
L’obiettivo è quello di rafforzare la verifica in due passaggi e limitare i rischi per le chiamate dai numeri sconosciuti. WhatsApp ha annunciato nuovi aggiornamenti finalizzati a migliorare la cybersicurezza degli utenti. Si andranno ad introdurre “ una verifica in due passaggi più robusta, il supporto a più passkey per lo stesso profilo e nuove informazioni sulle chiamate provenienti da numeri sconosciuti “. L’obiettivo è rendere la protezione dei profilo più semplice e accessibile per gli utenti, soprattutto nel momento in cui i tentativi di phishing e gli attacchi informatici sono diventati sempre più sofisticati. Per i cybercriminali , infatti, colpire direttamente su un dispositivo può portare molti vantaggi, sfruttando la chat come un vettore per rubare dati personali e denaro. Le novità Fino a oggi, spiega TechCrunch , la verifica in due passaggi di WhatsApp si basava su un PIN di sei cifre. Il suo impiego serviva come ulteriore livello di protezione nel caso in cui un malintenzionato fosse riuscito a ottenere il codice temporaneo necessario per accedere all’account. Con il nuovo aggiornamento , gli utenti potranno scegliere una password più lunga, composta da lettere, numeri e caratteri speciali, rendendola quindi più difficile da indovinare. Novità anche per le passkey , introdotte da WhatsApp nel 2024. Sarà da adesso possibile associare più di una passkey allo stesso profilo, una funzione particolarmente utile per chi utilizza sia dispositivi iOS sia Android . TechCrunch/WhatsApp Credits Le passkey offrono un livello di sicurezza superiore rispetto alle password tradizionali. Consentono infatti di accedere al proprio profilo attraverso sistemi biometrici come Face ID o l’impronta digitale. Eliminando la necessità di utilizzare le tradizionali combinazioni di nome utente e password , riducono inoltre “ il rischio di cadere vittima di attacchi di phishing “. Un ulteriore vantaggio è rappresentato dalla maggiore difficoltà per un eventuale cybercriminale di accedere da remoto all’account. Per sfruttare una passkey sarebbe infatti necessario avere accesso fisico al dispositivo sul quale è memorizzata la relativa chiave. WhatsApp sta inoltre introducendo nuove informazioni per le chiamate provenienti da numeri che non sono presenti nella rubrica. Su Android , gli utenti potranno vedere, ad esempio, se il numero appartiene a un altro Paese e se esistono gruppi in comune con la persona che sta effettuando la chiamata. Una nuova direzione Le nuove funzioni, sottolinea sempre TechCrunch , si aggiungono a una serie di aggiornamenti lanciati dall’azienda negli ultimi mesi. Alla fine di giugno WhatsApp ha introdotto gli username , permettendo agli utenti di condividere il proprio profilo senza dover necessariamente comunicare il numero di telefono. A fine maggio, invece, Meta – che possiede l’applicazione di messaggistica – ha lanciato un piano di abbonamento che offre funzionalità aggiuntive. Tra queste, anche la personalizzazione del profilo, le super reazioni e strumenti di analisi delle Storie. Il piano WhatsApp Plu s è stato introdotto insieme a iniziative simili denominate “ Plus ” per Instagram e Facebook . Seguici anche sul nostro canale WhatsApp Vai al sito di Cybersecurity Italia. L'articolo Cybersicurezza, WhatsApp annuncia nuove funzioni per migliorare la tutela degli utenti sembra essere il primo su CyberSecurity Italia .
cybersecitalia.itAug 26, 2026extracted
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023, before expanding to iOS in early 2024. Meta also followed it up by integrating passkeys into Facebook logins in June 2025. Users can manage their passkeys by navigating to Settings > Account > Passkeys. Along with the update, WhatsApp said it's adding a full password option as part of two-step verification, and users on Android will see more context on calls from people who aren't in their contacts. "Two-step verification is an extra protection layer that helps prevent someone from taking over your account, even if they get hold of your one-time passcode," WhatsApp said in a blog post shared with The Hacker News. "Until now it was a six-digit PIN, we've now upgraded it to a full password: longer, alphanumeric, and even with special ch@racters to make it harder to guess. If you've been using '123456,' this is your sign to upgrade." WhatsApp also noted that the extra context will include details like where the call is originating from, whether the person calling is already on their contact list, and if both parties are part of any common groups. "Scammers rely on urgency – now you can take a beat with some more info before answering," the messaging app said.
thehackernews.comAug 25, 2026extracted
New Zealand to pursue social media ban for children under 16
New Zealand to pursue social media ban for children under 16 The prime minister of New Zealand said Monday that his party plans to introduce legislation that would bar children under 16 from social media and mandate big fines for companies that do not adhere to the law. Prime Minister Christopher Luxon said he was eyeing penalties of up to 10% of a platform’s global revenue for violations. The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification. The bill also would require that platforms popular with children consistently monitor the risks they pose and report back on how they are identifying and mitigating those risks. Emerging tech like AI companions also will be subject to the framework, Luxon’s office said in a press release. The bill would also create an online safety regulator within the country’s Department of Internal Affairs to check that platforms are complying and crackdown when they are not. "We simply cannot accept the harm being done to a generation of New Zealand children," Luxon said in a statement. "Social media is exposing them to harmful content, addictive technology and pressures they are not equipped to deal with and it's affecting their family life, mental health, sleep and education." The proposed bill faces opposition from other New Zealand politicians and it is unclear how likely it is to become law. Social media bans are spreading worldwide with a number of European countries, Turkey, Brazil, Indonesia and Canada either pursuing legislation or implementing laws that have already passed. Australia became the first country to institute a ban for children under 16, but independent studies have shown that the law has been difficult to enforce and many young teens are still on the platforms. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaAug 24, 2026extracted
What happens to your data when you die? (Lock and Code S07E17)
This week on the Lock and Code podcast… You will die. Your data will not. The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out. As far back as 2007, Facebook was forced to reckon with mass grief when users asked the company to maintain the profile pages of the 32 victims killed by a school shooter at Virginia Tech that year. Those pages became de facto memorials for loved ones to fill with comments, and today, memorialization has become a full-fledged feature on both Facebook and Instagram. Platforms like YouTube, Pinterest, and LinkedIn—launched with likely zero strategy for a user’s death—now have procedures for next-of-kin to request that a deceased person’s account be deactivated. Now, think about all the other ways your data can linger after death. Every year, people accumulate more and digital stuff—email addresses, social media profiles, contact lists, domain names, subscription services, online banking accounts, and the phones, laptops, and tablets that hold it all—and every year, as that digital stuff accumulates, it compounds into ever more problems for someone else to sort out. Here, a small industry of digital estate planners have cropped up, helping families retrieve and preserve anything valuable, no matter how digital, from Spotify playlists, to poignant social media posts that mattered, to the photos stored on a phone. And where retrieval fails, artificial intelligence has offered an attempt at comfort. The chatbot service Replika launched in 2015 after its founder uploaded a dead friend’s text messages. HereAfter AI reportedly let users upload voice recordings to power a chatbot that sounded and spoke like the deceased. Film studios have pursued the same idea for entertainment, seeking to portray deceased actors in future films. Surprisingly, almost none of this activity is governed by law, said Tamara Kneese, author of the 2023 book “Death Glitch: How Techno-Solutionism Fails Us in This Life and Beyond.” “By and large, there is not a great legal mechanism for protecting the privacy rights of the dead,” said Kneese. “It may not be just that a grieving loved one decides to use a bunch of your data from all of your podcasts to create a chatbot to simulate interacting with you after you’re dead, but it may be that a company chooses, in some way, to use an aspect of your personality, of your demeanor, of your voice, of your likeness after your death without anyone really being aware.” Today, on the Lock and Code podcast with host David Ruiz, we speak with Kneese—Senior Research Scientist at Partnership on AI—about who owns a person’s data after they die, why every platform has invented its own private policy for the dead, and how the technology built to keep the dead close can vanish just as suddenly as they did. Or worse yet, as Kneese warned for those relying heavily on certain technologies in grief: “The company gets sold to someone else or disappears, goes bankrupt, and you no longer have that outlet or place for interaction when you’re mourning another time.” Tune in today to listen to the full conversation. Show notes and credits: Intro Music: “Spellbound” by Kevin MacLeod ( incompetech.com ) Licensed under Creative Commons: By Attribution 4.0 License http://creativecommons.org/licenses/by/4.0/ Outro Music: “Good God” by Wowa (unminus.com) Further reading: Fartein Hauan Nilsen, “Caring for the Algorithm: Care, Love, and the Relational Personhood of Chatbots,” Somatosphere , February 26, 2026 Fartein Hauan Nilsen, “ Therapeutic ideology and AI personhood: an anthropological inquiry into AI companionship ,” a chapter from “ Handbook on Anthropology and Artificial Intelligence ,” Edward Elgar Publishing, July 21, 2026 University of Birmingham, “New Model Rules mark meaningful step towards digital inheritance laws,” July 16, 2026 Edina Harbinja, “ Governing Digital Immortality: Artificial Intelligence, Deadbots and the Law ,” Edward Elgar Publishing, to be published September 2026 Lilian Edwards and Edina Harbinja, “Protecting Post-Mortem Privacy: Reconsidering the Privacy Interests of the Deceased in a Digital World,” May 2013, revised November 2013 Lilian Edwards, Edina Harbinja, and Marisa McVey, “Governing Ghostbots,” Computer Law & Security Review , November 2023 SAG-AFTRA, “SAG-AFTRA Statement on Today’s Passing of California Assembly Bill 1836,” August 31, 2024 Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it. Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our  exclusive offer for Malwarebytes Premium for Lock and Code listeners .
malwarebytes.comAug 24, 2026extracted
A week in security (August 17 – August 23)
Last week on Malwarebytes Labs: Zombie Card: An expired Visa credit card can be used for purchases Medical records, SSNs, and bank details exposed in CareCloud data breach ChatGPT for Teens tackles risky chats and homework shortcuts Twitch wants your content for Amazon AI training. Here’s how to opt out Your Mac already has a built-in firewall. Here’s how to get more from it 9 million images of people’s faces exposed by reverse lookup service 41 deceptive download sites show a real link, then send you somewhere else Sideloading on Android: What it is, why it’s risky, and how to do it more safely Scammers are using fake crypto AML checkers to drain your wallet Update Chrome now: Two critical vulnerabilities fixed Your polite reply to that text is worth $2 on the dark web Apple fixes another image-processing flaw that could allow code execution Be careful what you put in “anyone with the link” Google Docs Heights Finance data breach: What customers need to know ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw Fake TikTok rewards promise cash you’ll never get Update your Mac: Screen Sharing vulnerability exploited in the wild Why Facebook’s war on ad blockers could help scammers Stay safe! Something feel off? Check it before you click.    Malwarebytes Scam Guard  helps you analyze suspicious links, texts, and screenshots instantly.   Available with  Malwarebytes Premium Security  for all your devices, and in the  Malwarebytes app for iOS and Android .   Try it free →  
malwarebytes.comAug 24, 2026extracted
Senators press TikTok over withholding of safety features for some users
Senators press TikTok over withholding of safety features for some users Two U.S. senators are demanding answers from the social media giant TikTok following media reports that the company intentionally turned off security features for a subset of users to test how the protections would impact their engagement with the app. In a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users—including children—in order to determine whether protecting users would impact its financial bottom-line.” The missive follows reporting by Bloomberg earlier this month based off a confidential company document analyzing the account activity of Chase Nasca, a 16-year-old who killed himself in February 2022 after viewing a stream of content related to sadness and suicide. Nasca, the document revealed, was part of a control group comprising about 10 percent of the platform’s user base for which changes the company made to the algorithm to prevent repeated exposure to harmful subjects were withheld. The company review found the teen had viewed more than 7,500 videos in the two weeks leading up to his death, with 73% having themes of sadness or personal struggles and 10% violating the company’s rules around the normalization of suicide or self harm. “TikTok’s filter bubble prevention strategies did not take effect on this user by design,” the internal review found. In response to questions about the document, the company told Bloomberg: “We continue to invest significantly in Trust & Safety, including robust detection systems and dedicated enforcement teams that proactively remove content that violates our Community Guidelines.” TikTok did not immediately respond to a request for comment from Recorded Future News. In their letter, the senators pointed to the incident as an example of why they support the Kids Online Safety Act, which advanced out of the Senate Commerce Committee on August 5. “When signed into law, KOSA will address exactly the kind of conduct these disclosures raise: platforms designing products and algorithms to maximize addiction while children bear the consequences,” they said. Despite progress on the bill, it is unlikely it will pass during this legislative session, as differences remain over the inclusion of legal requirements for companies to prevent causing foreseeable harm. The senators requested answers by September 1 from the company to a list of questions related to what they called “experiments” in which A/B tests were conducted and security features were disabled for some users. They called on the company to release the full report surrounding Nasca’s death and queried why minors were included in control groups. The controversy coincides with a heavily watched trial this week involving Meta — the parent company of Facebook and Instagram — and four state attorneys general who accuse the company of deliberately making their products addictive to minors. James Reddick has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment.
therecord.mediaAug 20, 2026extracted
Your polite reply to that text is worth $2 on the dark web
Most wrong-number texts are harmless. Some are the first step in a carefully planned scam. By replying, you may be confirming that your number is active and that you’re willing to engage with strangers, making you a more valuable target for future fraud. Here’s why a polite response can be worth money to cybercriminals.  The politeness trap  Sunday night. You’re on the couch, half-watching Netflix, when your phone buzzes.  “Hey! Are we still on for dinner tomorrow? Don’t forget the wine ”   You don’t recognize the number. You glance at it for two seconds, then type what most polite people would:  “Sorry, I think you have the wrong number!”   You put your phone down. Go back to Netflix, and forget about it within five minutes.  On the other end, though, your reply has just told the sender something valuable. Not because of a technical exploit or an invisible cyber-attack, but because you just proved you’re the kind of person who responds to strangers politely.  According to cybercrime intelligence reports, responsive phone numbers are worth significantly more than inactive ones. With a single reply, you’ve entered a global criminal ecosystem run by transnational syndicates that, according to analysts , moves tens of billions of dollars.   What your reply told them  Let’s be clear: the “wrong number” text is not a phishing link. It’s not malware. In many cases, it’s not even the scam itself. It’s a personality test.   The scammers already have your number. They may have bought it in bulk from a data breach for a fraction of a cent per record. They already know the message was delivered because their SMS gateway received no delivery failure. Text messages remain one of the most effective ways to reach people, with exceptionally high open rates and most being read within minutes. That’s one reason scammers prefer SMS to email.  What they don’t know is whether you’re worth spending more time on. Your reply told them three useful things:   You’re responsive. You saw the message and felt compelled to reply. This immediately places you in their top 15–20% most active numbers category.   You’re polite. You didn’t ignore it and didn’t respond aggressively. You wanted to help a stranger. Scammers deliberately exploit that instinct to be polite and helpful.   You reply quickly. The time between their message and your reply can reveal how closely you monitor your phone, help estimate your timezone, and indicate how likely you are to respond to future messages. The two paths your number takes  From this moment, your story splits. Both paths described below play out across millions of phones worldwide.  Scenario A: The slow burn  Within minutes of your reply, another message arrives in response to yours:  “Oh no, I’m so sorry! But honestly, you seem like a really kind person. It’s rare to find polite people these days. I’m Sarah, by the way.”    Some people stop the conversation there. Others reply out of curiosity or because they’re simply being friendly. A few messages later, you’re in a conversation.  In some large scam operations, those early exchanges may be handled by AI (Artificial Intelligence) using open-source language models such as Llama or Mistral. That allows scammers to hold thousands of conversations at once and focus their time on the people who seem most likely to keep talking.   While keeping you engaged, the AI assigns you a real-time vulnerability score based on your response time and message length. If your score crosses a certain threshold, a human operator takes over. They read the conversation, learn your name, your job, and your communication style, then continue as though nothing has changed.  Within two or three weeks, this person has become a friend. They text you good morning, ask about your day, and send photos stolen from real social media profiles.  Around week three, they casually mention an investment:   “I’ve been making really good money on an investment platform lately. Almost $4,000 last month. It’s crazy.” If you show interest, they’ll send you a link to a fake trading platform with a convincing design. You might deposit $500 to test it. The next day, your dashboard shows a fake gain of $1,800, so you invest more. A week later, the platform disappears, along with your money, and the person who texted you every day.  According to the FBI’s Internet Crime Complaint Center (IC3), investment fraud generated more than $4.5 billion in reported losses in a single year. To be clear: while most wrong-number texts never reach this stage, victims who fall for so-called “pig butchering” scams (long-term romance/financial scams) suffer catastrophic average losses ranging between $70,000 and $75,000 per person.  Scenario B: The silent recycling  In this scenario, you replied “wrong number” and never heard from them again. You think you dodged the scam, but instead your number was simply moved to a different category: “Active, responsive, polite, but not susceptible to the wrong-number hook.”  That profile still has enormous commercial value. Your number is added to a cleaned database and sold or reused for a different campaign.   A week later you receive a text from another number:   “Hi! I saw your profile on LinkedIn. We have an opportunity that’s a perfect fit for your background.”   Or:  “Your package couldn’t be delivered, update your address by clicking here.”   Or a fake alert from your bank warning of “suspicious activity.”  You’ll probably never connect these messages to the wrong-number text you received the week before. They’re different topics and different senders. But they may all be part of the same criminal ecosystem. The first message was simply a way to sort potential targets. Everything that follows is the actual attack.  The most common hooks  If you’ve received one of these messages (or something very similar), you’re not alone. These are some of the most common opening lines used in wrong-number scams, tested on millions of people and optimized to maximize response rate:  The friend who doesn’t exist:   “Hey! See you tonight at 6? Don’t be late ”  “Are you still free tomorrow?”  “Did you send those files to the office?” “Hey Marco, are we still on for dinner tonight?”  The concerned neighbor:  “Sorry to bother you, I’ve noticed your dog sometimes runs into my yard.”  “I found a phone number on the dog tag, is this yours?”  “Hi, your package was delivered to my address by mistake.”  The professional mix-up:  “Hi, I tried to reach you about the delivery but you didn’t answer.”  “The shipment arrived at your address, can you confirm?”  “This is Mike from the office, did you get my earlier message?”  The family emergency:  “Do you know Sarah? There’s been an emergency.”  “Is this [common name]’s number? Something happened.”  The recruiter:  “Hi! I came across your profile, we have an incredible opportunity.”  “Hey, I’m reaching out about a position that matches your background perfectly.” If you’ve received one of these messages, it doesn’t automatically mean it’s a scam. People genuinely do text the wrong number sometimes. But if the conversation quickly moves to making small talk, asking personal questions, or encouraging you to keep chatting, stop replying.  Don’t recognize that number? We’ll check it. CHECK NOW The crime industry behind the text  These messages aren’t usually sent by a lone cybercriminal. They’re part of a highly organized criminal industry with its own market dynamics and global supply chains.  In January 2026, Cambodian and Chinese authorities arrested Chen Zhi, president of Prince Holding Group, accusing him of running a network of scam compounds across Southeast Asia where thousands of trafficked people were forced to manage these conversations. Those operations relied on underground marketplaces where criminals could buy everything they needed, from phone lists and stolen identities to AI tools and fake investment websites.  The scale is staggering. Blockchain analytics firm Elliptic estimates the Huione Guarantee underground marketplace processed more than $134 billion in transactions. Separately, researchers at the University of Texas at Austin estimate that pig-butchering scams stole more than $75 billion in cryptocurrency over four years.   The scam funnel: Costs and revenue  To understand why this ecosystem is so huge, look at the math. Sending hundreds of thousands of text messages costs very little. Even if only a tiny fraction of people reply, and an even smaller number eventually send money, the profits can far outweigh the costs.   Look at this illustrative model of a campaign sending 100,000 SMS messages:  The figures in this model aren’t arbitrary. They combine observed pricing from underground marketplaces such as Russian Market and BidenCash with average victim losses reported by law enforcement agencies, including the FBI’s Internet Crime Complaint Center (IC3).   Even allowing for variation between campaigns, the economics are compelling. A single campaign can cost less than $1,000 to run while generating more than $200,000 in revenue, representing a potential return on investment (ROI) of 90x to 200x.  Those same economics are reflected in underground marketplaces, where verified, enriched contact details command significantly higher prices than raw data. In our previous investigation into underground marketplaces , we found that a typical stolen personal record sold for around 95 cents. The more criminals learn about a potential victim, the more valuable that person’s data becomes.  The price ladder of your phone number:  .kb-table-container445707_d29b97-2a{overflow-x:auto;}.kb-table445707_d29b97-2a tr > *:nth-child(2){width:21%;}.kb-table445707_d29b97-2a{table-layout:fixed;width:100%;}.kb-table445707_d29b97-2a tr{height:0px;}.kb-table-container .kb-table445707_d29b97-2a th{padding-top:var(--global-kb-spacing-xxs, 0.5rem);padding-right:var(--global-kb-spacing-xxs, 0.5rem);padding-bottom:var(--global-kb-spacing-xxs, 0.5rem);padding-left:var(--global-kb-spacing-xxs, 0.5rem);text-align:left;}.kb-table-container .kb-table445707_d29b97-2a caption{text-align:center;}.kb-table-container .kb-table445707_d29b97-2a td{padding-top:var(--global-kb-spacing-xxs, 0.5rem);padding-right:var(--global-kb-spacing-xxs, 0.5rem);padding-bottom:var(--global-kb-spacing-xxs, 0.5rem);padding-left:var(--global-kb-spacing-xxs, 0.5rem);text-align:left;}.kb-table-container .kb-table445707_d29b97-2a td, .kb-table445707_d29b97-2a th{border-top:2px solid #CCCAD7;border-right:2px solid #CCCAD7;border-bottom:2px solid #CCCAD7;border-left:2px solid #CCCAD7;}@media all and (max-width: 1024px){.kb-table-container .kb-table445707_d29b97-2a td, .kb-table445707_d29b97-2a th{border-top:2px solid #CCCAD7;border-right:2px solid #CCCAD7;border-bottom:2px solid #CCCAD7;border-left:2px solid #CCCAD7;}}@media all and (max-width: 767px){.kb-table-container .kb-table445707_d29b97-2a td, .kb-table445707_d29b97-2a th{border-top:2px solid #CCCAD7;border-right:2px solid #CCCAD7;border-bottom:2px solid #CCCAD7;border-left:2px solid #CCCAD7;}} .kb-table-container .kb-table tr.kb-table-row445707_c65fe3-3f{background-color:rgba(0,89,255,0.17);height:48px;} Lead Type   Price   What Triggers It   Raw phone number (unverified, from old breach)  $0.01 – $0.05  Your data leaked years ago  Confirmed active number  $0.50 – $2.00  You replied “wrong number”  Enriched with profile data (name, job, income estimate)  $1.00 – $5.00  OSINT scripts scraped your socials  “Hot lead” (psychologically vulnerable, lonely, engaged)  $6.00 – $10.00  You chatted for 3+ days, showed openness  That’s a  4,000% value increase  generated by a single polite reply.    From there, scammers can enrich that record with publicly available information such as your name, employer, social media profiles, and estimated demographics using automated open-source intelligence (OSINT) techniques.  The more complete the profile becomes, the more valuable it is. Researchers monitoring underground marketplaces have found that enriched, pre-profiled contacts command premium prices because they’re more likely to become victims of high-value pig-butchering scams that generate billions of dollars in illicit revenue each year. How do they know who you are?  Before that text reaches your phone, your number may already have passed through automated script pipelines capable of cross-referencing tens of thousands of records in minutes.  Acquisition : Your number is pulled from historical data breaches, such as the Facebook leak affecting 533 million users, Twitter/X data leaks, or massive aggregated databases like Naz.api, and the Mother of All Breaches (MOAB), a collection of more than 26 billion records compiled from thousands of previous breaches.  Automated scraping : Software queries public sources to check whether your number is linked to an active WhatsApp account, collect your profile information and picture and match the number to public LinkedIn, Instagram, and Facebook profiles.  Data broker integration : Scammers exploit the same commercial data services used by marketing companies to associate a phone number with estimated age, address, and income bracket.  The result is a psychographic and commercial profile that helps scammers choose the most convincing approach. If your social media shows you have a dog, you might receive the neighbor hook: “Your dog keeps getting into my yard.” If you recently changed jobs on LinkedIn, the fake headhunter hook activates.  The human factor: Modern slavery  There’s one aspect of these scams that’s often overlooked: many of the people sending the messages are victims themselves.  In its August 9, 2023 policy report , the United Nations Office on Drugs and Crime (UNODC) described a human rights crisis tied to forced criminality in Southeast Asia. It estimates at least 120,000 people in Myanmar and tens of thousands in Cambodia are being held in fortified mega-compounds run by criminal syndicates.  Many were lured by fake job adverts promising legitimate work in digital marketing or customer service. Once they cross the border, their passports are confiscated. They were stripped of freedom and forced, under the threat of violence, to spend up to 16 hours a day managing dozens of scam conversations. Those who failed to meet financial targets were often beaten, isolated, or sold to other compounds.  When you reply to one of these messages, you’re interacting with a system designed to simultaneously exploit your financial availability and the enslavement of another human being.  Breaking the chain  You can’t erase your number from dark web databases: that damage may have done years ago. But you can make your profile far less valuable to scammers.  Make yourself harder to profile : Review the privacy settings on any messaging apps and social media platforms that use your phone number. Limit who can see information such as your profile photo, status, last seen, and phone number. The less information scammers can gather automatically, the harder it is to build a detailed profile about you. On WhatsApp, for example, you can set Profile Photo , About , Status , and Last Seen to My Contacts . On Telegram, set Phone Number to Nobody .  Report before you block: Blocking protects only you. Reporting protects everyone. When you use WhatsApp’s Report and Block function, the last five messages in the chat are sent to Meta’s security teams. If enough people report the same number, it may be permanently banned, destroying the entire active campaign on that line.  The golden rule: If you receive an unexpected message from an unknown number, the safest response is no response at all . Don’t reply, don’t explain yourself, and don’t worry about seeming impolite. If it’s a genuine wrong number, the sender will usually realise their mistake and move on. If it’s a scam, you’ve denied the criminals exactly what they wanted: proof that your number is active and that you’re willing to engage.   Something feel off? Check it before you click.    Malwarebytes Scam Guard  helps you analyze suspicious links, texts, and screenshots instantly.   Available with  Malwarebytes Premium Security  for all your devices, and in the  Malwarebytes app for iOS and Android .   Try it free →  
malwarebytes.comAug 19, 2026extracted
Cyber Incident Disrupts Student Services at UT San Antonio
IT systems at the University of Texas (UT) San Antonio have been taken offline following a cyber incident, causing significant disruption to student registrations and payments ahead of the start of term this week. A statement released by university leaders on August 17 revealed that the institution had identified “attempted unauthorized activity” at the edge of its network, before reaching core systems. At this point, University Technology Solutions (UTS) took action with expert partners to contain the activity, resulting in some systems being taken offline so a thorough evaluation of the environment can take place and to assess whether additional protections need to be implemented. UT San Antonio claimed its response has been effective. So far, there has been no evidence that data was accessed or exfiltrated as a result of the unauthorized activity. The institution acknowledged that the shut down of IT systems is causing disruption for its community ahead of the start of term on August 19. “With classes beginning this Wednesday, we recognize how important, reliable access to university systems and services is for our students, faculty and staff. Our teams are working with great care to ensure that our technology environment is both available and secure as we begin the new academic year,” the statement read. These disruptions have impacted online registration and tuition payments. Extensions have been granted for students to complete these processes. University phone systems were not available according to a 12.30pm CST update on August 17, but were expected to be restored later that day. An update on the University’s Facebook page at 5.30pm CST on August 17 said that students, faculty and staff would be sent instructions to reset their passphrases on Tuesday, August 18. Education a Major Target at Start of Term Educational institutions, including schools, colleges and universities, have been heavily targeted by cyber-attacks at the start of the new academic year over recent years. This is likely because IT systems are under extra pressure at these times, with activities such as registering for classes, paying tuition and accessing course information taking place. Ross Filipek, CISO at Corsica Technologies, commented, “Taking major systems offline at that moment creates immediate pressure to get everything running again. Whether that timing was intentional isn’t clear. Still, attackers understand that disruption carries more weight when an organization is already operating at maximum capacity. Universities are no different from hospitals or retailers in that respect. The more painful downtime becomes, the more leverage an attacker potentially gains.” Filipek praised UT San Antonio for detecting and containing the incident early but highlighted the importance of segmentation to prevent wider systems being affected by these measures. “Cyber resilience means being able to contain a threat without forcing the rest of the organization to choose between security and keeping the doors open,” he added. Image credit: JHVE / Shutterstock.com
infosecurity-magazine.comAug 18, 2026extracted
Loading 40 more…