Search/philips
Vendor

philips

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
tasy webportal
Connections
98 relationships
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has named more than 40 organizations allegedly targeted in the recent campaign that exploited a vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. The vulnerability and its exploitation The exploitation of the vulnerability, tracked as CVE-2026-12569, came to light in June, when CISA added it to its KEV catalog and the vendor warned of attacks targeting it. The flaw is an improper input validation issue that allows a remote, unauthenticated attacker to achieve arbitrary code execution via specially crafted requests. Exploitation of the vulnerability was expected, with police in Germany reportedly alerting organizations about imminent attacks. It’s worth noting that CVE-2026-12569 is the first ever Windchill vulnerability to be exploited in the wild. The cybersecurity industry reported seeing exploitation of the PLM product flaw in Cl0p ransomware attacks in late July. Cl0p affiliates exploited the security hole to deliver web shells that gave them access to the data of organizations using Windchill. Security firm ReliaQuest reported on Tuesday that Cl0p has been using a custom implant designed to provide “full data theft capability” without requiring additional tools. “[The web shell] maps sensitive vault data, decrypts every credential in the Windchill keystore, and includes a custom Java class loader that lets Clop execute any additional code inside the application process, extending the shell into an unlimited backdoor for follow-on activity such as lateral movement, ransomware, or persistence,” ReliaQuest explained. Cl0p attacks The Cl0p cybercrime gang initially only listed partial company names on its website, but on August 12 it started releasing alleged victims’ full names. More than 40 organizations apparently targeted in the Windchill campaign have been named to date. For each victim, the hackers listed the type and amount of information they have stolen. The type of exfiltrated data includes databases, project files, backups, photographs and other image files, engineering documents, blueprints, diagrams, logs, and other corporate documents. The amount of stolen information per organization ranges between 1 GB and several terabytes, according to the hackers. The compromised files could contain sensitive personal information and valuable intellectual property, but much of it may be of little value and already in the public domain, which is why many of the targeted organizations have likely refused to pay a ransom. The list of alleged victims includes oil and gas giant Shell, tech giant Philips, fintech giant Fiserv, enterprise mobility provider Zebra Technologies, industrial equipment manufacturer Ingersoll Rand, point-of-sale software maker Toast, global medical technology leader Mindray, and key Apple camera lens supplier Largan Precision. GE was initially listed as well, but it has since been removed from the Cl0p website, which could indicate that the company has agreed to pay a ransom or has resumed negotiations with the hackers. Companies such as Shell, Philips, Fiserv and GE stated that they are aware of the claims and are investigating, but none has confirmed a significant data breach. Cl0p previously conducted similar data theft and extortion campaigns targeting vulnerabilities in Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere software. Related: CareCloud Data Breach Impact Grows to 3.7 Million Individuals Related: Heights Finance Data Breach Impacts at Least 1.2 Million Individuals Related: 680,000 Impacted by French Tax Authority Data Breach
securityweek.comAug 19, 2026extracted
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers. "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," Philips said in a statement shared with Reuters. "This has no impact on customer environments." GE and Philips spokespersons have yet to reply after BleepingComputer also reached out to them for more details and to confirm the Clop ransomware gang's claims. This comes after oil giant Shell also said on Friday that it is investigating a potential security incident after the Clop hacking group claimed it stole 89GB of data. "We are aware of a potential incident," a Shell spokesperson told BleepingComputer when asked to confirm the gang's data theft claims. "We are working with our security teams and relevant experts to investigate. While the three companies have yet to share more information, the Clop gang has listed them on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks exploiting a critical improper input validation vulnerability (tracked as CVE-2026-12569) against Internet-exposed PTC Windchill and PTC FlexPLM instances. PTC says the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. The company says more than 30,000 customers globally use its products, including over 1,500 brand and retail customers using FlexPLM. In these attacks, Clop claims it stole a wide range of sensitive data from the companies' compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to Shell, GE, and Philips. PTC began releasing CVE-2026-12569 security patches on June 17 and urged customers to review environments for indicators of compromise (IOCs) in a private advisory, even though there was no confirmation of in-the-wild exploitation. Since then, cybersecurity company ReliaQuest and the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) have confirmed Clop's Windchill and FlexPLM attacks, in which the threat actors have been deploying JSP webshells to steal sensitive data from victims' compromised PLM platforms. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks after PTC warned of "heightened threat activity" on June 26, mandating federal agencies to secure their PTC Windchill and FlexPLM instances within three days after adding it to its catalog of known exploited vulnerabilities. This vulnerability has also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch systems as quickly as possible. The Clop extortion gang has a long history of targeting enterprise platforms in data theft attacks, breaching Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers in previous campaigns, with the latter affecting over 2,770 organizations worldwide. Starting in early August 2025, it also began exploiting an Oracle EBS zero-day flaw to steal sensitive files from many organizations. The list of victims includes many high-profile organizations worldwide, including The Washington Post, GlobalLogic, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The U.S. Department of State now offers a $10 million reward for any information linking the cybercrime gang's attacks to a foreign government. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 17, 2026extracted
Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily. According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans. "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer when asked to confirm Clop's data theft claims. While the company has yet to share more information, the Clop gang listed it on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569. As part of the same attacks, Clop also claimed it stole sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of tech conglomerates General Electric and Philips. GE and Philips spokespersons were not immediately available for comment when BleepingComputer contacted them earlier today. A PTC spokesperson has also yet to reply to a request for comment. PTC began releasing CVE-2026-12569 security patches on June 17 and, even though it didn't confirm in-the-wild exploitation, it also released a private advisory urging customers to review environments for indicators of compromise (IOCs). After PTC warned customers of "heightened threat activity" on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog, and ordering federal agencies to secure their PTC Windchill and FlexPLM instances within three days. CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch their systems as quickly as possible. Clop's Windchill and FlexPLM attacks were also confirmed by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats, and by cybersecurity company ReliaQuest, which said that the threat actors have been deploying JSP webshells that allow them to steal sensitive data from victims' compromised PLM platforms. PTC FlexPLM and PTC Windchill are enterprise software platforms in the Product Lifecycle Management (PLM) category, used to track, design, and manage products up to final manufacturing. The two systems are widely popular among engineering, manufacturing, quality, and supply chain teams at high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says that its products are used by over 30,000 customers globally, including more than 1,500 brand and retail customers using FlexPLM. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 14, 2026extracted
Smart TV e tracciamento dei dati: il ruolo delle VPN nella tutela della privacy domestica
All’interno del perimetro della rete domestica, oggi sempre più interconnessa con le infrastrutture aziendali grazie anche allo smart working, la Smart TV rappresenta uno dei vettori di tracciamento e una delle potenziali superfici di attacco meno monitorate. In questo scenario, l’adozione di soluzioni VPN, Virtual Private Network, non risponde più soltanto a logiche di intrattenimento o di sblocco geografico dei cataloghi di streaming, ma si configura come una contromisura architetturale necessaria per la limitazione del data harvesting e la protezione dell’integrità del traffico di rete. Indice degli argomenti Dal punto di vista della sicurezza informatica, la Smart TV costituisce un elemento di criticità sistemica per tre fattori principali: Ciclo di vita delle patch ridotto: a differenza di sistemi operativi per PC o smartphone, i firmware delle Smart TV ricevono aggiornamenti di sicurezza per un lasso di tempo limitato. Dispositivi commercializzati solo pochi anni fa si trovano oggi privi di difese contro vulnerabilità note. Assenza di strumenti di endpoint protection: non è possibile installare agenti di sicurezza (EDR/antivirus) tradizionali sul sistema operativo di una TV, rendendo difficile il rilevamento di eventuali anomalie nel traffico o compromissioni software. Lateral movement (movimento laterale): in una rete non segmentata, la compromissione della Smart TV offre agli attori malevoli una testa di ponte ideale per condurre scansioni della LAN e tentare l’esfiltrazione di dati da dispositivi critici adiacenti, come i laptop aziendali utilizzati in regime di lavoro agile. L’efficacia di una Virtual Private Network applicata a un ecosistema Smart TV non si misura sulla base dell’estetica dell’interfaccia utente, ma dipende da vincoli architetturali ben precisi: Efficienza computazionale del protocollo: i SoC (System on Chip) integrati nei televisori sono ottimizzati per la decodifica video hardware, non per processi di crittografia intensivi. L’utilizzo di protocolli obsoleti o pesanti (come OpenVPN con cifratura AES-256-CBC) può causare vistosi colli di bottiglia, surriscaldamento del chip e conseguente degradazione del frame rate. È fondamentale orientarsi verso soluzioni che supportino implementazioni basate su WireGuard o protocolli proprietari leggeri basati su cifratura ChaCha20. Modalità di deployment (Native App vs. Router-level): la frammentazione dei sistemi operativi rappresenta il principale ostacolo. Android TV (Sony, Philips) e la più recente Apple TV (da tvOS 17) offrono supporto nativo alle applicazioni VPN. Al contrario, sistemi proprietari diffusi come Tizen (Samsung) o webOS (LG) non permettono l’installazione diretta di client. In questi scenari, la protezione deve essere delegata a monte, configurando la VPN direttamente sul router della LAN o sfruttando soluzioni Smart DNS (sebbene queste ultime offrano solo l’offuscamento geografico e non la cifratura del traffico). 🌍 Server: 8.000+ server in 129 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 74% NordVPN si distingue per lo sviluppo di NordLynx, un protocollo proprietario basato sul codice sorgente di WireGuard. NordLynx risolve il limite nativo di WireGuard relativo all’assegnazione degli IP statici introducendo un sistema di Network Address Translation (NAT) doppio e dinamico. Questo garantisce che nessun dato identificativo dell’utente venga memorizzato sul server, coniugando un throughput elevato (essenziale per flussi UHD/4K) a una rigorosa architettura zero-logs. Sotto il profilo della sicurezza perimetrale, l’applicazione integra la funzionalità Threat Protection Pro operante a livello di rete. Questa agisce come un filtro DNS avanzato, intercettando e bloccando le richieste verso domini noti per il phishing, i malware IoT e i tracker pubblicitari legati ai sistemi di ACR degli OEM. L’intera infrastruttura di NordVPN poggia su server RAM-only (diskless), il che significa che il sistema operativo e tutti i dati temporanei risiedono esclusivamente nella memoria volatile, azzerandosi a ogni ciclo di alimentazione o in caso di intrusioni fisiche nei data center. La conformità delle politiche di non-registrazione è regolarmente verificata tramite audit indipendenti condotti da enti terzi come Deloitte. NordVPN propone tre piani d’abbonamento: Base, Plus, Ultimate distribuiti su tre cicli di fatturazione differenti. 2 anni, 1 anno, 1 mese. Rappresenta l’opzione ideale se i servizi di sicurezza perimetrale e di gestione dell’identità sono già delegati ad agent o appliance di terze parti all’interno della LAN. Include l’accesso completo alla rete globale di oltre 9.400 server RAM-only, il protocollo NordLynx, la protezione DNS standard, il monitoraggio base del dark web (Dark Web Monitor™ fino a 5 email) e la copertura di 10 dispositivi simultanei. Opzione 2 anni, sconto 74%): 2,99 €/mese, fatturazione anticipata di 71,76 € per i primi 24 mesi; rinnovo successivo a 139,08 €/anno. Opzione 1 anno, sconto 61%: 4,49 €/mese, fatturazione anticipata di 53,88 € per i primi 12 mesi; rinnovo successivo a 139,08 €/anno. Opzione mensile, sconto 0%: 11,59 €/mese, fatturazione flat ricorrente senza vincoli). Questo livello introduce moduli attivi sul traffico dati, configurandosi come una soluzione ottimale per proteggere la Smart TV e gli altri endpoint dai tentativi di tracciamento e inoculazione di codice malevolo. Aggiunge infatti la suite Threat Protection Pro™ (protezione anti-malware basata su intelligenza artificiale, blocco avanzato di ad e tracker pubblicitari, protezione email illimitata) e include il Password Manager multipiattaforma (NordPass) con annesso Data Breach Scanner. Opzione 2 anni, sconto 76%: 3,49 €/mese, fatturazione anticipata di 83,76 € per i primi 24 mesi; rinnovo a 179,88 €/anno. Opzione 1 anno, sconto 67%: 4,89 €/mese, fatturazione anticipata di 58,68 € per i primi 12 mesi; rinnovo a 179,88 €/anno. Opzione mensile, sconto 0%: 13,69 €/mese. Progettato per una mitigazione del rischio a 360 gradi, il piano Ultimate estende la protezione oltre il perimetro informatico rigido, introducendo tutele legali e finanziarie. Include lo strumento Dark Web Monitor Pro™ (esteso a 8 indirizzi email, numeri di telefono, carte di credito e documenti d’identità), un modulo per il rilevamento delle truffe telefoniche e dello spam (con ID chiamante integrato per Android), 1 TB di spazio di archiviazione cloud crittografata (NordLocker) e un servizio per la rimozione dei dati personali dai registri dei data broker (Incogni). L’elemento di maggiore novità per i professionisti del settore è l’integrazione di un’Assicurazione Cyber dedicata (disponibile nativamente per i residenti in Italia): Copertura Finanziaria Corporate/Consumer: Il pacchetto assicurativo prevede un massimale di copertura fino a 5.000 € destinato al recupero delle perdite finanziarie derivanti da truffe informatiche e al rimborso dei costi legali e amministrativi sostenuti a seguito di un furto d’identità accertato. Opzione 2 anni, sconto 71%: 6,19 €/mese, fatturazione anticipata di 148,56 € per i primi 24 mesi; rinnovo a 256,68 €/anno. Opzione 1 anno, sconto 64%): 7,59 €/mese, fatturazione anticipata di 91,08 € per i primi 12 mesi; rinnovo a 256,68 €/anno. Opzione mensile, sconto 0%): 19,39 €/mese. Tutti i piani mantengono intatte le clausole di salvaguardia finanziaria della garanzia di rimborso entro 30 giorni dall’acquisto iniziale. Qualora l’esito dei test di compatibilità e throughput sulla Smart TV o sul router non soddisfacesse i requisiti minimi di targa della LAN, l’utente può recedere con restituzione integrale del capitale anticipato tramite l’assistenza clienti attiva 24/7. 🌍 Server: 4500+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’88% + 3 mesi gratis 🔥 Surfshark adotta un modello di offerta modulare ripartito su tre livelli di servizio, studiati per integrare funzioni di protezione dell’identità e rimozione dei dati personali: Surfshark Starter: comprende i moduli core della VPN, il sistema di mascheramento della geolocalizzazione, il generatore di proxy email e dati sintetici Alternative ID (essenziale per prevenire il tracciamento dei database di profilazione degli OEM) e la suite CleanWeb per il blocco di annunci, tracker, pop-up per il consenso dei cookie e attacchi di phishing a livello DNS. Surfshark One: integra lo stack Starter con un sistema Antivirus completo operante in tempo reale (incluso il monitoraggio delle scansioni pianificate e la protezione della webcam), il motore di ricerca privato Surfshark Search (esente da tracing pubblicitario) e la piattaforma Alert per il monitoraggio in tempo reale dei data leak relativi a email, carte di credito e documenti d’identità. Surfshark One+: rappresenta il livello di massima protezione dell’identità digitale, integrando nativamente l’accesso completo a Incogni. Questo servizio gestisce in modo automatizzato le istanze legali per la rimozione dei dati personali dell’utente dai database dei data broker e dai siti di ricerca di persone, agendo direttamente alla radice della filiera del data harvesting. La sostenibilità economica di Surfshark è legata alle forti economie di scala dei contratti a lungo termine. Rappresenta l’opzione a più alto ROI, con tassi di sconto che raggiungono l’87% grazie all’inclusione di tre mensilità omaggio nel primo periodo di fatturazione (27 mesi totali). VPN Surfshark Starter (Sconto 87%): 1,99 €/mese (Fatturazione anticipata una tantum di 53,73 € per i primi 27 mesi; al termine del periodo promozionale la fatturazione diventa annuale). VPN Surfshark One (Sconto 87%): 2,29 €/mese (Fatturazione anticipata di 61,83 € per i primi 27 mesi). VPN Surfshark One+ (Sconto 80%): 4,19 €/mese (Fatturazione anticipata di 113,13 € per i primi 27 mesi). Configura una soluzione intermedia per l’allocazione del budget a breve termine, applicando lo sconto su un totale iniziale di 15 mesi di servizio. VPN Surfshark Starter, sconto 79%): 3,19 €/mese, fatturazione anticipata di 47,85 € per i primi 15 mesi). VPN Surfshark One, sconto 81%): 3,39 €/mese, fatturazione anticipata di 50,85 € per i primi 15 mesi). VPN Surfshark One+, sconto 66%): 6,99 €/mese, fatturazione anticipata di 104,85 € per i primi 15 mesi). Opzione flat utile esclusivamente per finalità di testing o auditing transitorio della rete, priva di sconti commerciali. VPN Surfshark Starter, sconto 0%): 15,45 €/mese, addebito mensile ricorrente. VPN Surfshark One, sconto 0%): 17,95 €/mese. VPN Surfshark, One+, conto 0%: 20,85 €/mese. Tutti i piani includono una garanzia di rimborso entro 30 giorni dall’acquisto iniziale, offrendo una finestra di recesso completo qualora l’efficienza dei protocolli di tunneling (WireGuard o OpenVPN) non si dimostrasse idonea alle metriche della Smart TV o del gateway perimetrale della LAN. Per gli amministratori di sistema, la piattaforma offre inoltre la possibilità di integrare un modulo per l’IP Dedicato (disponibile su 20 località geografiche) per bypassare i controlli CAPTCHA ed evitare fenomeni di IP blacklisting legati all’uso di indirizzi condivisi. 🇮🇹 Posizioni server in Italia: Milano e Palermo 🌍 Server: 20.017 in 145 Paesi 📱 Massimo dispositivi: 10 🆓 Versione Free: ✔ 💻 Compatibilità: Phone, Android, Mac, Windows, Linux, Fire TV Stick, Chromebook, Android TV, Apple TV 🔐 Sicurezza: Crittografia AES-256 con supporto a WireGuard e OpenVPN 👨💻 Assistenza 24/7: e-mail e ticket (risposta entro 24 ore) 🏢 Sede legale: Svizzera 🔥 Offerte attive: SCONTO fino al 70% Il posizionamento di Proton VPN si distingue per un approccio radicale alla trasparenza architetturale e alla conformità legale. Sviluppato da Proton AG (la tech company svizzera fondata dagli scienziati del CERN nota per ProtonMail), il servizio poggia su fondamenta ingegneristiche e di governance uniche rispetto ai concorrenti di proprietà di grandi conglomerati della sicurezza (come Kape o Nord Security): Codice 100% open source con audit pubblico: a differenza dei modelli closed source, la totalità delle applicazioni di Proton VPN è liberamente ispezionabile dal punto di vista del codice sorgente e viene sottoposta a rigorosi audit periodici eseguiti da laboratori di sicurezza terzi indipendenti (es. Securitum). Trasparenza No-Log validata: la politica di non-registrazione dei log non è una semplice dichiarazione commerciale, ma un’impostazione strutturale pubblicata apertamente, che certifica l’impossibilità di archiviare tabelle di routing, timestamp di sessione o payload dei singoli pacchetti. Giurisdizione elvetica Extra-UE: avendo sede legale in Svizzera, Proton opera al di fuori dei trattati internazionali di intelligence (quali le alleanze 5/9/14 Eyes). Le richieste di esfiltrazione di dati da parte di autorità estere non hanno valore legale diretto se non convalidate da un ordine restrittivo della Corte Federale Svizzera, in un contesto normativo ad altissima tutela della privacy. Per compensare il sovraccarico di rete generato dai protocolli di cifratura avanzati (AES-256 e ChaCha20), Proton ha ingegnerizzato la tecnologia VPN Accelerator. Questo framework ottimizza l’instradamento dei pacchetti superando le limitazioni intrinseche del codice dei server Linux e potenziando il throughput fino al 400% sui collegamenti a lunga distanza. Per una Smart TV, ciò si traduce nella garanzia di flussi ad alta velocità esenti da fenomeni di buffer o instabilità del jitter. Il controllo perimetrale dei dati a livello di trasporto è demandato a NetShield, un modulo integrato che combina un ad-blocker nativo a un sistema di blocco malware basato su liste di reputazione DNS. NetShield agisce a monte dell’endpoint, impedendo alla Smart TV di avviare connessioni outbound verso domini dannosi o server di tracciamento pubblicitario legati ai protocolli ACR. La struttura d’offerta di Proton VPN si concentra su un unico abbonamento premium denominato Proton VPN Plus, che sblocca l’accesso all’intero ecosistema di oltre 20.000 server distribuiti in 140 paesi. Il servizio supporta la protezione simultanea di 10 dispositivi, l’utilizzo di server DNS personalizzati, la compatibilità nativa per Smart TV (Android TV, tvOS, Firestick) e router, oltre a funzionalità avanzate come lo Split Tunneling, le connessioni LAN e il Double Hop (instradamento concatenato multi-server per la massima resilienza all’analisi del traffico). Rappresenta il punto di massima efficienza finanziaria con una riduzione del prezzo di listino pari al 70%. Costo mensile equivalente: 2,99 €/mese Schema di fatturazione: addebito anticipato una tantum di 71,76 € per i primi 24 mesi. Al termine del primo biennio promozionale, il servizio si rinnova automaticamente a una tariffa standard di 83,88 € ogni 12 mesi (pari a 6,99 €/mese). Il risparmio netto sul primo ciclo è di 168 €. Applica una contrazione dei costi operativi pari al 60%, utile per allocazioni di budget a breve termine o test infrastrutturali prolungati. Costo mensile: 3,99 €/mese Schema di fatturazione: addebito anticipato di 47,88 € per i primi 12 mesi. I successivi rinnovi mantengono la tariffa flat di 83,88 € ogni 12 mesi. Il risparmio iniziale sul listino è di 72 €. Opzione pensata esclusivamente per attività di proof-of-concept, auditing temporaneo o analisi forense di rete all’interno della LAN. Costo mensile: 9,99 €/mese Schema di fatturazione: Addebito ricorrente mensile di 9,99 €, privo di sconti o ammortamenti temporali. Tutte le formule di abbonamento beneficiano della garanzia di rimborso entro 30 giorni dall’attivazione. Questo approccio di vendita risk-free consente ai progettisti di rete di implementare Proton VPN sul proprio gateway domestico o aziendale, testare il comportamento dei SoC delle Smart TV sotto crittografia simmetrica e procedere all’eventuale recesso con storno integrale della transazione qualora i KPI prestazionali non risultassero allineati agli standard richiesti. ⚙️ Numero di server: 3.000+ 🌍 Aree geografiche: 160 🗺️ Paesi: 105 📍 IP dedicato: ❌ 📱 Device massimi supportati: fino a 5 dispositivi 🔐 Sicurezza: OpenVPN, IKEv2, Lightway 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% L’infrastruttura di ExpressVPN si colloca sulla fascia premium del mercato, giustificata da un’evoluzione ingegneristica orientata alla resilienza contro le minacce future e alla massima ottimizzazione del throughput. La suite si sviluppa su tre pilastri tecnologici proprietari: Protezione post-quantistica: ExpressVPN integra nativamente algoritmi di crittografia post-quantistica all’interno del proprio tunnel. Questa architettura difende il traffico dati dagli attacchi di tipo Harvest Now, Decrypt Later (immagazzinamento odierno del traffico cifrato da parte di attori statali o malevoli, volto alla decifrazione futura tramite computer quantistici). Protocollo Lightway (Core in Rust): abbandonando le implementazioni standard, ExpressVPN ha sviluppato Lightway, un protocollo open source con core interamente riscritto in Rust. Questa scelta ingegneristica azzera i difetti di memory-safety tipici del C, riduce le linee di codice per facilitare gli audit e garantisce una velocità di commutazione dei server quasi istantanea, ideale per flussi streaming 4K stabili su Smart TV. Tecnologia TrustedServer: la rete si estende su 105 paesi e opera esclusivamente su server basati su memoria RAM volatile. Poiché i nodi non scrivono mai su disco rigido, l’intero stack software e i dati di transito vengono completamente polverizzati a ogni ciclo di riavvio elettrico, garantendo l’applicazione fisica della politica di zero-log. La suite integra il sistema Threat Manager, che opera a livello di gateway bloccando preventivamente i tracker, i domini di phishing e i siti per adulti. Per i dispositivi sprovvisti di supporto nativo alle VPN, ExpressVPN include il servizio DNS MediaStreamer, utile per lo sblocco geografico rapido senza l’overhead della crittografia. I piani superiori estendono la protezione oltre il perimetro di rete tramite ExpressKeys (gestore di password con report sulla vulnerabilità delle credenziali), ExpressMailGuard (generatore di alias email anonimi) ed ExpressAI (assistente IA privato). A partire dal 2026, l’offerta commerciale di ExpressVPN abbandona la tariffazione a SKU singola per strutturarsi su tre differenti tier di servizio: Base, Avanzato, Pro, distribuiti su tre cicli di fatturazione. Rappresenta l’opzione a più alto ROI per l’ammortamento dei costi fissi, estendendo la copertura iniziale a 28 mesi totali. ExpressVPN Base (cconto 80%): 2,29 €/mese. Addebito anticipato una tantum di 64,12 € per i primi 28 mesi. Successivamente si rinnova a 79,95 €/anno. Include 10 connessioni simultanee e protezione di rete Lite. Risparmio totale: 257,60 €. ExpressVPN Avanzato (sconto 76%): 2,99 €/mese. Addebito anticipato di 83,72 € per i primi 28 mesi. Successivamente si rinnova a 109,95 €/anno. Eleva i dispositivi a 12, sblocca ExpressKeys, 100 alias email e piani eSIM inclusi (holiday.com). Risparmio totale: 266,00 €. ExpressVPN Pro (sconto 71%): 4,99 €/mese. Addebito anticipato di 139,72 € per i primi 28 mesi. Successivamente si rinnova a 179,95 €/anno. Supporta 14 dispositivi, IP Dedicato incluso, alias email illimitati ed ExpressAI (500 crediti/giorno). Risparmio totale: 350,00 €. ExpressVPN: 12 mesi + 3 mesi extra: caratteristiche tecniche e costi Soluzione intermedia focalizzata sulla flessibilità di budget, con copertura iniziale riscaldata su 15 mesi totali. ExpressVPN Base, sconto 69%): 3,49 €/mese, fatturazione anticipata di 52,35 € per i primi 15 mesi; rinnovo a 79,95 €/anno. Risparmio: 120,00 €. ExpressVPN Avanzato, sconto 64%): 4,49 €/mese, fatturazione anticipata di 67,35 € per i primi 15 mesi; rinnovo a 109,95 €/anno. Risparmio: 120,00 €. ExpressVPN Pro, sconto 62%): 6,49 €/mese, fatturazione anticipata di 97,35 € per i primi 15 mesi; rinnovo a 179,95 €/anno. Risparmio: 165,00 €. Profilo flat privo di sconti o agevolazioni temporali, consigliato esclusivamente per attività di auditing e test prestazionali. ExpressVPN Base: 11,49 €/mese, rinnovi automatici mensili ricorsivi. ExpressVPN Avanzato: 12,49 €/mese. ExpressVPN Pro: 17,49 €/mese, include IP dedicato e moduli IA. Tutti i contratti attivati prevedono una garanzia di rimborso entro 30 giorni dedicata ai nuovi utenti. In caso di performance non allineate ai flussi UHD o di incompatibilità con i router della LAN, il recesso consente lo storno completo dei canali di pagamento utilizzati. L’integrazione di una Smart TV all’interno di un’infrastruttura di rete domestica o aziendale introduce vettori di vulnerabilità legati al tracciamento dei dati (tecnologie ACR – Automatic Content Recognition) e alla potenziale esfiltrazione di informazioni sensibili da parte di firmware IoT scarsamente aggiornati. Per mitigare questi rischi e massimizzare le prestazioni dei flussi streaming in 4K, l’approccio ingegnerisico richiede la separazione logica del traffico e la centralizzazione della VPN a livello di perimetro. La prima linea di difesa per la messa in sicurezza della LAN prevede la creazione di una VLAN dedicata ai dispositivi IoT e Smart TV (es. VLAN 20), mantenendo i dispositivi di produzione (PC, NAS, smartphone) isolati sulla rete principale (VLAN 10). Isolamento del traffico (Layer 2): configurando regole di firewall sul router/gateway perimetrale, si deve interdire qualsiasi comunicazione cross-VLAN originata dalla VLAN 20 verso la VLAN 10. La Smart TV deve poter stabilire esclusivamente connessioni outbound verso l’esterno (Internet) e rispondere solo a sessioni autorizzate provenienti dalla rete protetta (es. per il mirroring locale). Mitigazione del Broadcast: isolare la Smart TV in una subnet dedicata riduce il rumore di broadcast della rete principale, ottimizzando le risorse di calcolo del SoC (System on Chip) del televisore, spesso limitato sul piano hardware. [INTERNET] ──> [Gateway / Firewall] │ ├─> [VLAN 10: Produzione] ──> PC / NAS / Smartphone (Dati Protetti) │ └─> [VLAN 20: IoT/Smart TV] ──> Centralizzazione VPN (No Accesso a VLAN 10) Sebbene i principali provider analizzati, NordVPN, Surfshark, Proton VPN, ExpressVPN, offrano applicazioni native per Android TV, tvOS Apple TV e Firestick, la centralizzazione del tunnel sul router perimetrale (o su un router in cascata dedicato come la soluzione ExpressVPN Aircove) rappresenta la scelta architetturale più efficiente per i seguenti motivi: Sgravio computazionale dell’endpoint: la decifratura e cifratura dei pacchetti tramite protocolli complessi (quali WireGuard o Lightway) richiede cicli di CPU intensivi. Demandando questo carico hardware al processore del router, si azzerano i micro-scatti e i problemi di buffering causati dal surriscaldamento del SoC della Smart TV. Protezione dei dispositivi legacy (MediaStreamer e Smart DNS): alcuni sistemi operativi per Smart TV (es. WebOS di LG o Tizen di Samsung) non supportano nativamente l’installazione di client VPN. Operando a livello di router, l’intero traffico della VLAN 20 viene incapsulato nel tunnel in modo trasparente rispetto al sistema operativo dell’endpoint. In alternativa, l’uso di DNS personalizzati (come il MediaStreamer di ExpressVPN o lo Smart DNS di NordVPN) configurati staticamente sulla TV permette lo sblocco geografico senza cifratura, minimizzando l’overhead di rete. Per garantire la continuità dei flussi UHD (Ultra High Definition) ed evitare degradazioni prestazionali dovute alla contemporaneità dei download sulla rete, è necessario implementare politiche di controllo della larghezza di banda: Assegnazione delle priorità (QoS): sul router deve essere impostata una regola di QoS basata sull’indirizzo IP statico o sul MAC Address della Smart TV, classificando il suo traffico come High Priority per i pacchetti multimediali (RTP/RTSP). Ottimizzazione della MTU (Maximum Transmission Unit): l’incapsulamento VPN aggiunge un overhead ai pacchetti IP. Per evitare fenomeni di frammentazione del payload – che causerebbero latenza e buffering nello streaming – è consigliabile ottimizzare il valore di MTU sul router (tipicamente riducendolo a un valore compreso tra 1420 e 1440 byte se si utilizza WireGuard/Lightway, rispetto ai 1500 byte standard delle connessioni WAN). L’adozione combinata di una VLAN isolata e di un tunnel VPN centralizzato sul gateway permette di coniugare le esigenze di sicurezza perimetrale e conformità dei dati con le massime metriche di stabilità e throughput richieste dall’intrattenimento ad altissima definizione.
cybersecurity360.itMay 26, 2026extracted
Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
Nine vulnerabilities in the open source Digital Imaging and Communications in Medicine (DICOM) server Orthanc allow attackers to crash servers, leak data, and execute arbitrary code remotely. A lightweight standalone DICOM server for healthcare and medical research, Orthanc supports the automated analysis of medical images and does not require complex database administration or third-party dependencies. The nine security defects in Orthanc, tracked CVE-2026-5437 to CVE-2026-5445, are rooted in insufficient validation of metadata, missing checks, and unsafe arithmetic operations, CERT Coordination Center (CERT/CC) notes in an advisory. The first bug is an out-of-bounds read issue affecting the meta-header parser, caused by insufficient input validation in the parsing logic. Next is a GZIP decompression bomb flaw in the processing of specific HTTP requests. Because no limit is enforced on decompressed size, and memory is allocated based on attacker-controlled metadata, a malicious payload could be used to exhaust system memory. Another memory exhaustion defect was discovered in ZIP archive processing, where the server trusts metadata describing the uncompressed size of the archived files, allowing an attacker to forge size values and cause the server to allocate extremely large buffers during extraction. The HTTP server was also found to allocate memory directly based on user-supplied header values, allowing attackers to craft an HTTP request containing an extremely large length value, triggering server termination. Orthanc’s decompression routine for the proprietary Philips Compression format is affected by an out-of-bounds read vulnerability, where escape markers at the end of the compressed data stream are improperly validated. “A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output,” the CERT/CC advisory reads. Another out-of-bounds read weakness was identified in the lookup-table decoding logic for Palette Color images, which fails to validate pixel indices. The flaw can be exploited via crafted images with indices larger than the palette size. The last three security defects are heap buffer overflow issues impacting the image decoder, Palette Color image decoding logic, and PAM image parsing logic. Successful exploitation of these vulnerabilities could lead to out-of-bounds memory access. “The most severe issues are heap-based buffer overflows in image parsing and decoding logic, which can crash the Orthanc process and may, under certain conditions, provide a pathway to remote code execution (RCE),” the CERT/CC advisory reads. Orthanc versions 1.12.10 and earlier are affected by these bugs. Users are advised to update to version 1.12.11, which addresses all of them. The vulnerabilities were discovered by researchers at Machine Spirits, who published their own advisories. Related: Critical Marimo Flaw Exploited Hours After Public Disclosure Related: Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users Related: Data Leakage Vulnerability Patched in OpenSSL Related: RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years
securityweek.comApr 10, 2026extracted
New cybersecurity laws and trends in 2026 | Kaspersky official blog
The outgoing year of 2025 has significantly transformed our access to the Web and the ways we navigate it. Radical new laws, the rise of AI assistants, and websites scrambling to block AI bots are reshaping the internet right before our eyes. So what do you need to know about these changes, and what skills and habits should you bring with you into 2026? As is our tradition, we’re framing this as eight New Year’s resolutions. What are we pledging for 2026?… Get to know your local laws Last year was a bumper crop for legislation that seriously changed the rules of the internet for everyday users. Lawmakers around the world have been busy: Banning social media for teens Introducing strict age verification (think scanning your ID) procedures to visit certain categories of websites Requiring explicit parental consent for minors to access many online services Applying pressure through blocks and lawsuits against platforms that wouldn’t comply with existing child protection laws — with Roblox finding itself in a particularly bright spotlight Your best bet is to get news from sites that report calmly and without sensationalism, and to review legal experts’ commentaries. You need to understand what obligations fall on you, and, if you have underage children — what changes for them. You might face difficult conversations with your kids about new rules for using social media or games. It’s crucial that teenage rebellion doesn’t lead to dangerous mistakes such as installing malware disguised as a “restriction-bypassing mod”, or migrating to small, unmoderated social networks. Safeguarding the younger generation requires reliable protection on their computers and smartphones, alongside parental control tools. But it’s not just about simple compliance with laws. You’ll almost certainly encounter negative side effects that lawmakers didn’t anticipate. Master new methods of securing access Some websites choose to geoblock certain countries entirely to avoid the complexities of complying with regional regulations. If you’re certain your local laws allow access to the content, you can bypass these geoblocks by using a VPN. You need to select a server in a country where the site is accessible. It’s important to choose a service that doesn’t just offer servers in the right locations, but actually enhances your privacy — as many free VPNs can effectively compromise it. We recommend Kaspersky VPN. Brace for document leaks While age verification can be implemented in different ways, it often involves websites using a third-party verification service. On your first login attempt, you’ll be redirected to a separate site to complete one of several checks: take a photo of your ID or driver’s license, use a bank card, or nod and smile for a video, and so on. The mere idea of presenting a passport to access adult websites is deeply unpopular with many people on principle. But beyond that, there’s a serious risk of data leaks. These incidents are already a reality: data breaches have impacted a contractor used to verify Discord users, as well as service providers for TikTok and Uber. The more websites that require this verification, the higher the risk of a leak becomes. So what can you do? Prioritize services that don’t require document uploads. Instead, look for those utilizing alternative age verification methods such as a micro-transaction charge to a payment card, confirmation through your bank or another trusted external provider, or behavioral/biometric analysis. Pick the least sensitive and easiest-to-replace document you have, and use only that one for all verifications. “Least sensitive” in this case means containing minimal personal data, and not referencing other primary identifiers like a national ID number. Use a separate, dedicated email address and phone number in combination with that document. For the sites and services that don’t verify your identity, use completely different contact details. This makes it much harder for your data to be easily pieced together from different leaks. Learn scammers’ new playbook It’s highly likely that under the guise of “age verification”, scammers will begin phishing for personal and payment data, and pushing malware onto visitors. After all, it’s very tempting to simply copy and paste some text on your computer instead of uploading a photo of your passport. Currently, ClickFix attacks are mostly disguised as CAPTCHA checks, but age verification is the logical next step for these schemes. How to lower these risks? Carefully check any websites that require verification. Do not complete the verification if you’ve already done it for that service before, or if you landed on the verification page via a link from a messaging app, search engine, or ad. Never download apps or copy and paste text for verification. All legitimate services operate within the browser window, though sometimes desktop users are asked to switch to a smartphone to complete the check. Analyze and be suspicious of any situation that requires entering a code received via a messaging app or SMS to access a website or confirm an action. This is often a scheme to hijack your messaging account or another critical service. Install reliable security software on all your computers and smartphones to help block access to scam sites. We recommend Kaspersky Premium — it provides: a secure VPN, malware protection, alerts if your personal data appears in public leaks, a password manager, parental controls, and much more. Cultivate healthy AI usage habits Even if you’re not a fan of AI, you’ll find it hard to avoid: it’s literally being shoved into each everyday service: Android, Chrome, MS Office, Windows, iOS, Creative Cloud… the list is endless. As with fast food, television, TikTok, and other easily accessible conveniences, the key is striking a balance between the healthy use of these assistants and developing an addiction. Identify the areas where your mental sharpness and personal growth matter most to you. A person who doesn’t run regularly lowers their fitness level. Someone who always uses GPS navigation gets worse at reading paper maps. Wherever you value the work of your mind, offloading it to AI is a path to losing your edge. Maintain a balance: regularly do that mental work yourself — even if AI can do it well — from translating text to looking up info on Wikipedia. You don’t have to do it all the time, but remember to do it at least some of the time. For a more radical approach, you can also disable AI services wherever possible. Know where the cost of a mistake is high. Despite developers’ best efforts, AI can sometimes deliver completely wrong answers with total confidence. These so-called hallucinations are unlikely to be fully eradicated anytime soon. Therefore, for important documents and critical decisions, either avoid using AI entirely, or scrutinize its output with extreme care. Check every number, every comma. In other areas, feel free to experiment with AI. But even for seemingly harmless uses, remember that mistakes and hallucinations are a real possibility. How to lower the risk of leaks. The more you use AI, the more of your information goes to the service provider. Whenever possible, prioritize AI features that run entirely on your device. This category includes things like the protection against fraudulent sites in Chrome, text translation in Firefox, the rewriting assistant in iOS, and so on. You can even run a full-fledged chatbot locally on your own computer. AI agents need close supervision. The agentic capabilities of AI — where it doesn’t just suggest but actively does work for you — are especially risky. Thoroughly research the risks in this area before trusting an agent with online shopping or booking a vacation. And use modes where the assistant asks for your confirmation before entering personal data — let alone buying anything. Audit your subscriptions and plans The economics of the internet is shifting right before our eyes. The AI arms race is driving up the cost of components and computing power, tariffs and geopolitical conflicts are disrupting supply chains, and baking AI features into familiar products sometimes comes with a price hike. Practically any online service can get more expensive overnight — sometimes by double-digit percentages. Some providers are taking a different route, moving away from a fixed monthly fee to a pay-per-use model for things like songs downloaded or images generated. To avoid nasty surprises when you check your bank statement, make it a habit to review the terms of all your paid subscriptions at least three or four times a year. You might find that a service has updated its plans and that you need to downgrade to a simpler one. Or a service might have quietly signed you up for an extra feature you’re not even aware of — and you need to disable it. Some services might be better switched to a free tier or canceled altogether. Financial literacy is becoming a must-have skill for managing your digital spending. To get a complete picture of your subscriptions and truly understand how much you’re spending on digital services each month or year, it’s best to track them all in one place. A simple Excel or Google Docs spreadsheet works, but a dedicated app like SubsCrab is more convenient. It sends reminders for upcoming payments, shows all your spending month-by-month, and can even help you find better deals on the same or similar services. Prioritize the longevity of your tech The allure of powerful new processors, cameras, and AI features might tempt you to buy a new smartphone or laptop in 2026, but planning for making it last for several years should be a priority. There are a few reasons… First, the pace of meaningful new features has slowed, and the urge to upgrade frequently has diminished for many. Second, gadget prices have risen significantly due to more expensive chips, labor, and shipping — making major purchases harder to justify. Furthermore, regulations like those in the EU now require easily replaceable batteries in new devices, meaning the part that wears out the fastest in a phone will be simpler and cheaper to swap out yourself. So, what does it take to make sure your smartphone or laptop reliably lasts several years? Physical protection. Use cases, screen protectors, and maybe even a waterproof pouch. Proper storage. Avoid extreme temperatures, don’t leave it baking in direct sun or freezing overnight in a car at -15°C. Battery care. Avoid regularly draining it to single-digit percentages. Regular software updates. This is the trickiest part. Updates are essential for security to protect your phone or laptop from new types of attacks. However, updates can sometimes cause slowdowns, overheating, or battery drain. The prudent approach is to wait about a week after a major OS update, check feedback from users of your exact model, and only install it if the coast seems clear. Secure your smart home The smart home is giving way to a new concept: the intelligent home. The idea is that neural networks will help your home make its own decisions about what to do and when, all for your convenience — without needing pre-programmed routines. Thanks to the Matter 1.3 standard, a smart home can now manage not just lights, TVs, and locks, but also kitchen appliances, dryers, and even EV chargers! Even more importantly, we’re seeing a rise in devices where Matter over Thread is the native, primary communication protocol, like the new IKEA KAJPLATS lineup. Matter-powered devices from different vendors can see and communicate with each other. This means you can, say, buy an Apple HomePod as your smart home central hub and connect Philips Hue bulbs, Eve Energy plugs, and IKEA BILRESA switches to it. All of this means that smart and intelligent homes will become more common — and so will the ways to attack them. We have a detailed article on smart home security, but here are a few key tips relevant in light of the transition to Matter. Consolidate your devices into a single Matter fabric. Use the minimum number of controllers, for example, one Apple TV + one smartphone. If a TV or another device accessible to many household members acts as a controller, be sure to use password security and other available restrictions for critical functions. Choose a hub and controller from major manufacturers with a serious commitment to security. Minimize the number of devices connecting your Matter fabric to the internet. These devices — referred to as Border Routers — must be well-protected from external cyberattacks, for example, by restricting their access at the level of your home internet router. Regularly audit your home network for any suspicious, unknown devices. In your Matter fabric, this is done via your controller or hub, and in your home network — via your primary router or a feature like Smart Home Monitor in Kaspersky Premium.
kaspersky.comDec 19, 2025extracted
Chip Programming Firm Data I/O Hit by Ransomware
Chip programming solutions provider Data I/O was recently targeted in a ransomware attack that has caused significant disruption to the company’s operations. Data I/O offers electronic device programming systems for integrated circuits, such as flash memory and microcontrollers. According to its website, Data I/O customers include Bosch, Amazon, Apple, Google, HP, Microsoft, Siemens, Philips, Sony, and Foxconn. In an 8-K form filed with the SEC on August 21, the company revealed that it detected ransomware on some IT systems on August 16. It took some platforms offline in response to the intrusion, which led to communications, shipping, manufacturing, and other functions getting disrupted. Data I/O has called in outside experts to help with incident response and recovery. The investigation is ongoing, but the wording in the SEC report suggests the cybercriminals may have stolen some data from hacked systems. “Based on the findings, the Company will take additional actions as appropriate, including notifying affected individuals and regulatory authorities in compliance with applicable laws,” the firm said. The company has been working on restoring impacted systems, but on August 21 it could not provide a timeline for full restoration. “The expected costs related to the incident, including fees for our cybersecurity experts and other advisors, and costs to restore any impacted systems, are reasonably likely to have a material impact on the Company’s results of operations and financial condition,” the company said. No known ransomware group appears to have taken credit for the attack on Data I/O. Related: Telecom Firm Colt Confirms Data Breach as Ransomware Group Auctions Files Related: Pharmaceutical Company Inotiv Confirms Ransomware Attack Related: US Seizes $2.8 Million From Zeppelin Ransomware Operator Related: Manpower Says Data Breach Stemming From Ransomware Attack Impacts 140,000
securityweek.comAug 25, 2025extracted
Pwn2Own Offers $1m for Zero-Click WhatsApp Exploit
Security researchers attending the upcoming Pwn2Own competition in Cork have the chance to win $1m if they can find a high-impact exploit in WhatsApp. The competition organizers, Trend Micro’s Zero Day Initiative (ZDI), explained late last week that only zero-click vulnerabilities that lead to code execution would be considered for the six-figure cash prize, although smaller awards will be available for other WhatsApp exploits. “We introduced this category last year, but no one attempted it. Perhaps a number with two commas will provide the needed motivation,” said ZDI head of threat awareness, Dustin Childs. The upcoming event, which will take place in Trend Micro’s Cork office from October 21 to 24, is the second time the competition will be held in Ireland. It is focused on consumer products, with eight categories selected: Mobile phones Messaging The SOHO Smashup Smart home devices Printers NAS devices Surveillance system devices Wearables Meta is the main sponsor of the event this year, with Synology and QNAP also putting money into the competition, as well as helping to set up and configure devices for contestants to probe for bugs. As always, the idea is to incentivize some of the world’s most talented security researchers to find exploits in a range of products. This information will then be responsibly disclosed for the relevant vendors to fix, while enabling Trend Micro to protect customers with virtual patches until a full update is available. “We’ve tweaked the mobile category a bit by adding a new USB attack vector for the phones. Hopefully, we’ll see some interesting research come in demonstrating what could happen if a threat actor has physical access to your device,” said Childs. “Last year, we awarded $1,066,625 for over 70 unique zero-day vulnerabilities at the contest. We can’t wait to see if 2025 tops that number – especially with a million-dollar bounty on the table.” Mobile handsets will sit at the “heart of this event,” with contestants able to hack a Samsung Galaxy S25, Google Pixel 9 and an Apple iPhone 16. Other products in the competition will include QNAP, Ubiquiti and Nest SOHO devices, Amazon, Philips and Sonos smart home devices, Meta Quest headsets and Ray-Ban Smart Glasses. Zero-click WhatsApp exploits are often discovered and monetized by commercial spyware companies like NSO Group, which used it to deliver its notorious Pegasus malware. Image credit: Diego Thomazini / Shutterstock.com
infosecurity-magazine.comAug 4, 2025extracted