Search/ray-ban
Vendor

ray-ban

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
stories rw4003 65582v 48-23 firmware
Connections
15 relationships
What’s wrong with Meta’s NameTag feature and why you should be wary of it | Kaspersky official blog
Tech giants are taking another shot at smart glasses. The idea has long captivated the minds of sci-fi writers and their biggest fans — the denizens of Silicon Valley. Many will remember Google Glass, the first real attempt at creating such a device back in 2012. It went down as one of Google’s few major flops. Following Google’s glaring failure, other tech giants such as Meta, Apple, and Microsoft temporarily shelved the idea of sleek, lightweight glasses in favor of bulkier VR headsets. One of the main reasons for the shift was that the tech back in the 2010s simply wasn’t advanced enough to pack high-end features and decent battery life into a compact pair of glasses. Since then, however, much has changed. Now, tech giants are doing a 180 and pivoting back to smart glasses for everyday use. For instance, just this past June, Snap (the company behind Snapchat) dropped a new version of its glasses called SPECS. Rumor has it that Apple might unveil its own take on the tech later this year. For now, though, the collaboration between Ray-Ban and Meta is the undisputed king of the market. They launched their most advanced smart glasses in 2025, selling over 7 million pairs that year alone. However, Ray-Ban Meta glasses have been plagued by a string of ugly controversies since early 2026. They all center around a feature that would allow the glasses’ camera to recognize faces within its field of view. When activated, the feature would notify the user whenever the system identified someone. What exactly are Ray-Ban Meta glasses? Ray-Ban and Meta first teamed up in 2020. At the time, these sleek, high-tech glasses were envisioned as a tie-in for the Metaverse — tech guru Mark Zuckerberg’s massive VR project. As it turned out, the glasses outlived the project they were built for. But let’s not rub salt in Zuckerberg’s wounds. In 2021, Ray-Ban and Meta dropped their first collab: the Ray-Ban Stories glasses. Two years later, the next generation hit the shelves, rebranded simply as Ray-Ban Meta. Then, in 2025, Zuckerberg himself unveiled the AI-powered Ray-Ban Meta Gen 2 glasses. That’s the version we’re looking at today. Unlike the original Ray-Ban Meta glasses, Gen 2 is pitched as a gadget for workouts and everyday life. Initially, the companies offered two frame models — Wayfarer and Headliner — both available in a variety of colors. The lenses come in different tint levels: standard clear, dark sunglasses, or photochromic. Prescription lenses are also available for an extra fee. Meta later rolled out a few more frame options, including the Oakley Meta HSTN and the Oakley Meta Vanguard (Oakley being another eyewear brand owned by the same parent company as Ray-Ban, EssilorLuxottica). Regardless of the frame model, all these devices pack the same core features: Capturing POV photos and videos Playing music, podcasts, and other audio content Making phone calls Sending and receiving messages using voice commands Translating speech in real time with support for multiple languages Converting speech to text Reading out notifications and messages Creating voice notes and reminders Broadcasting first-person video for WhatsApp and Messenger video calls Navigating the map through spoken prompts Answering user questions about surroundings and objects in view Meta smart glasses operate using several built-in components. First, the glasses are equipped with a camera for taking photos and recording videos directly from your eye line. Second, the temples house open-ear speakers. These let you listen to music, get directions, take calls, and hear Meta AI’s responses without blocking out the world with earbuds — a questionable perk if you value audio privacy. Finally, the glasses have several built-in microphones used for phone calls, voice command recognition, and interacting with the AI assistant. What most Meta smart glasses lack, though, is a screen. Only the priciest, top-tier model — the Meta Ray-Ban Display — actually features a built-in display. Every photo and video captured by the glasses’ camera, along with the device settings, is stored in the Meta AI companion app, which syncs the glasses with a smartphone. It’s this combination of camera, mics, speakers, and the Meta AI app that allows the device to analyze its surroundings and respond to user queries in real time. Compared to something like the Apple Vision Pro, Meta’s gadgets are relatively inexpensive, hovering around the $400 to $500 mark. What’s more, Meta just dropped a brand-new line under its own name, Meta Glasses, starting at an even lower $299. With price tags like that, the idea of these things going mainstream isn’t sci-fi anymore. That makes the reports about the NameTag feature all the more alarming. According to journalists and researchers, this feature is designed to recognize people who enter the glasses’ field of view. Let’s dig into the details. NameTag: the feature that ‘doesn’t exist’ Information leaked from internal Meta documents regarding the development of a facial recognition feature for the company’s smart glasses emerged, by eerie coincidence, on Friday, February 13, 2026. The leaked data reveals that the feature, internally dubbed NameTag, would use Meta’s built-in AI assistant to identify people caught within the glasses’ camera view and provide the device owner with information about them. According to the leak, Meta considered two ways to run NameTag. The first version would only recognize people from the user’s existing contacts across Meta’s services. The second version would be much broader and could identify anyone with a public profile on the company’s social media platforms: Instagram, Facebook, and potentially WhatsApp and Messenger. If that gives you the creeps, fear not. The tech giant, famously known for its “oh so totally ironclad” commitment to user privacy, was quick to issue a reassuring statement: “Our competitors offer this type of face-recognition product; we do not. If we were to release such a feature, we would take a very thoughtful approach before rolling anything out.” Proof of this thoughtful approach emerged just a few months later. In June 2026, Wired reported that Meta had quietly embedded facial recognition tech for its smart glasses into the Meta AI app. According to journalists, the code had been slipped into the software bit by bit over several months, starting in January 2026. How the supposedly nonexistent feature works At the time the investigative report was published, NameTag wasn’t available to users. However, according to Wired, the code required to run it was already present in the Meta AI companion app, which is used by owners of the company’s smart glasses and installed on over 50 million smartphones. NameTag relies on three AI models to do its thing. The first model detects faces within the camera’s field of view. The second isolates and crops those facial images. The third converts those images into unique biometric prints. According to Wired, all three models had already been pulled from Meta’s servers and were sitting on users’ devices. Once officially launched, the app would take that biometric print and cross-reference it with a database of similar prints stored on the glasses owner’s smartphone. What’s more, journalists claim this database was already configured to pull live updates from Meta. It seems plausible that such a database could be built from public user profiles across Meta’s platforms, including photos that users upload to Instagram or Facebook themselves. For now, though, we can only guess. Since the feature doesn’t officially exist, Meta hasn’t publicly explained how these profiles are created. Once a match was found, the system would notify the user that a person had been identified. However, the tech wouldn’t simply ignore the faces it couldn’t match. Those images were slated to be automatically cropped, indexed, and stashed away in a separate folder labeled “Pending”. Some UI elements of the Meta AI app — seemingly related to NameTag — were implemented and accessible to users in the May 2026 update. In that version, the feature went by the much tamer name “Connections”. According to its description, it was designed to help users “remember people they’ve met”. Obviously, this tech is a dream come true for stalkers, scammers, creeps, and anyone else looking to dig up dirt on strangers. All it takes is a glance to unlock someone’s digital identity and all the data attached to it. The broader privacy implications are equally important. The ability to remain anonymous among strangers has always been the norm. Tech like NameTag drags us closer to a fishbowl reality where your face serves as a universal ID tag, and every casual encounter can trigger an instant background check in the digital world. Giving mass access to this kind of technology is precisely the sort of brain blast you’d expect from tech bros who still can’t get anyone to talk to them at a bar. Luckily, NameTag’s exposure and the ensuing public backlash have resulted in the code powering this feature vanishing from the latest version of the app — for now. The feature is gone, but the questions remain The day after the Wired story broke, Meta dropped a new version of the app, scrubbing almost all the code tied to NameTag. VP of Communications Andy Stone doubled down, saying journalists should ignore the evidence right in front of them no such feature exists. Meanwhile, privacy advocates point out that Meta could restore the NameTag code to users’ apps just as easily as they removed it. It’s way too early to let our guard down. A few weeks later, Wired dropped yet another bombshell article about NameTag and facial recognition. Journalists managed to get their hands on a licensing agreement between Meta and Rank One Computing, a company that builds facial recognition tech for US law enforcement and military agencies. Notably, their client roster reportedly includes the Naval Criminal Investigative Service (NCIS), US Special Operations Command (USSOCOM), and various police departments. Meta purchased the rights to use Rank One Computing’s facial recognition tech and “liveness detection” system, which can distinguish a real person from a photo, video, or mask. According to the license terms, the software can handle a database of up to 10 million biometric profiles. Before NameTag was yanked, Wired noted that Rank One Computing’s facial recognition technology and associated software components were already baked into the Meta AI app, though they were just sitting there dormant and unavailable to users. For years, the use of facial recognition tech by law enforcement has sparked intense debates over the boundaries of acceptable surveillance. Therefore, the prospect of similar capabilities appearing in a consumer device that absolutely anyone can buy and use is, to put it mildly, controversial — especially when it can link a random passerby’s face to their digital profiles. Both companies declined to comment on the partnership. How to preserve what’s left of your privacy in a dystopian world The thought of military-grade tech being packed into consumer devices is enough to send a shiver down any sane person’s spine. Unfortunately, we have to face reality: protecting yourself from eyewear capable of facial recognition is going to be pretty tough. But that doesn’t mean you shouldn’t try. Right now, there’s no way to opt out of having your face scanned by Meta’s glasses. However, there is a way to spot these little spies in your vicinity. A tech enthusiast named Yves Jeanrenaud has already built an app that warns users whenever smart glasses are nearby. Called Nearby Glasses, the app is already available on both Android and iOS. The app detects Meta and Snap glasses by sniffing out the Bluetooth signals they broadcast to communicate with other devices. Of course, this method isn’t foolproof and can trigger some false alarms. Still, Nearby Glasses at least gives you a heads-up that a device capable of covertly recording you and scanning your surroundings might be lurking close by. If you’re especially worried about your privacy, installing an app like this is a smart move. It can be particularly helpful for people in high-risk groups, such as stalking survivors, sex workers, or undocumented immigrants. For those who aren’t quite ready to go full-on paranoid, we highly recommend setting your Meta accounts to private. Granted, this won’t stop smart glasses from capturing your face, and it’s not a foolproof shield against potential recognition. However, restricting access to your photos, contact lists, and other personal details helps cut down on the data that could potentially be weaponized to identify you and map out your digital footprint. If you’re not sure how tight your social media security actually is, we recommend checking out our free online tool – Privacy Checker. It gives you step-by-step instructions on how to tune your privacy and security settings across different social networks and online platforms, helping you shrink the amount of personal info floating around out there for strangers to see.
kaspersky.comJul 9, 2026extracted
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
Another week in cybersecurity. Another week of "you've got to be kidding me." Attackers were busy. Defenders were busy. And somewhere in the middle, a whole lot of people had a very bad Monday morning. That's kind of just how it goes now. The good news? There were some actual wins this week. Real ones. The kind where the good guys showed up, did the work, and made a dent. It doesn't always happen, so when it does, it's worth noting. The bad news? For every win, there's a fresh headache waiting right behind it. New tricks, old tricks dressed up in new clothes, and a few things that'll make you want to go touch grass and never log back in. But you will. We all do. So here's everything that mattered this week — the wins, the warnings, and the stuff you really shouldn't ignore. ⚡ Threat of the Week Tycoon 2FA and LeakBase Operations Dismantled — The infrastructure hosting the Tycoon2FA service, which Europol said was among the largest adversary-in-the-middle (AitM) phishing operations worldwide, has been dismantled by a coalition of security companies and law enforcement agencies. "Taking down infrastructure associated with Tycoon 2FA and identifying the individual allegedly responsible for creating this prolific hacking tool will have a significant impact on overall MFA credential phishing, and hopefully strike a blow to the world's most prolific AitM phishing-as-a-service," Proofpoint said in a statement shared with The Hacker News. Phishing kits and PhaaS platforms have become an Achilles' heel in recent years, streamlining and democratizing phishing attacks for less technically savvy hackers by providing them with a suite of tools to create convincing emails and phishing pages that unsuspecting victims will engage with. For a relatively modest fee, aspiring cybercriminals can subscribe to these services and carry out phishing attacks at scale. In a similar development, authorities also took down LeakBase, one of the world's largest online forums for cybercriminals to buy and sell stolen data and cybercrime tools. While the disruption is a positive development, it's known that such takedowns typically create only short-term disruptions, as the ecosystem adapts by migrating to other forums or more resilient distribution channels, like Telegram. Shadow AI Is EVERYWHERE. Here's How You Can Find and Secure It Shadow AI is quietly accessing sensitive data across your SaaS environment. Learn how to close AI blind spots and get ahead of data exposure risks with this new guide. Get Answers Now ➝ 🔔 Top News Anthropic Finds 22 Firefox Vulnerabilities in Firefox — Anthropic said it discovered 22 new security vulnerabilities in the Firefox web browser using its Claude Opus 4.6 large language model (LLM)as part of a security partnership with Mozilla. Of these, 14 have been classified as high, seven have been classified as moderate, and one has been rated low in severity. The issues were addressed in Firefox 148, released late last month. The vulnerabilities were identified over a two-week period in January 2026. The company noted that the cost of identifying vulnerabilities is cheaper than creating an exploit for them, and the model is better at finding issues than at exploiting them. Qualcomm Flaw Exploited in the Wild — A high-severity security flaw impacting Qualcomm chips used in Android devices has been exploited in the wild. The vulnerability in question is CVE-2026-21385 (CVSS score: 7.8), a buffer over-read in the Graphics component that could result in memory corruption and arbitrary code execution. There are currently no details on how the vulnerability is being exploited in the wild. However, Google acknowledged in its monthly Android security bulletin that "there are indications that CVE-2026-21385 may be under limited, targeted exploitation." Coruna iOS Exploit Kit Uses 23 Exploits Against Older iOS Devices — Google disclosed details of a new and powerful exploit kit dubbed Coruna (aka CryptoWaters) targeting Apple iPhone models running iOS versions between 13.0 and 17.2.1. The exploit kit featured five full iOS exploit chains and a total of 23 exploits, the company said. What makes it different is that it started with a commercial surveillance vendor in February 2025, got picked up by what seems like a Russian espionage group targeting Ukrainians in July 2025, and ended up in the hands of financially motivated attackers in China going after crypto wallets by the end of the year. Coruna began its life as a surveillance exploit kit, but by the time it reached the Chinese cybercrime gang, it was heavily focused on financial theft. It's not known how the exploit kit got passed between multiple threat actors of varied motivations. This has raised the possibility of a secondhand market where it's resold to other threat actors, who end up repurposing them for their own objectives. Transparent Tribe Unleases Vibeware Against Indian Entities — In a new attack campaign detected by Bitdefender, the Pakistan-aligned threat actor known as Transparent Tribe has leveraged artificial intelligence (AI)-powered coding tools to vibe-code malware and use them to target the Indian government and its embassies in multiple foreign countries. These tools are written in niche programming languages like Nim, Zig, and Crystal so as to evade detection. "Rather than a breakthrough in technical sophistication, we are seeing a transition toward AI-assisted malware industrialization that allows the actor to flood target environments with disposable, polyglot binaries," the company said. Iranian Hackers Target U.S. Entities Amid Conflict — The Iranian hacking group tracked as MuddyWater (aka Seedworm) targeted several U.S. companies, including banks, airports, non-profit, and the Israeli arm of a software company, as part of a campaign that began in early February 2026, and continued after the joint U.S.-Israel military strikes on Iran towards the end of the month. The development comes against the backdrop of hacktivist-fueled cyber attacks, with wiper campaigns targeting Israeli energy, financial, government, and utilities sectors. "The trajectory is clear: what began as nation-state-level ICS capability in 2012 [with Shamoon wiper] has become, by 2026, something any motivated actor can attempt with free tools and an internet connection," CloudSEK said in a report last week. "The technical barrier has collapsed. The threat pool has expanded. And the US attack surface has never been larger." Another targeted campaign has distributed a trojanized version of the Red Alert rocket warning Android app to Israeli users via SMS messages impersonating official Home Front Command communications. Once installed, the malware monitors and abuses the granted permissions to collect sensitive data, including SMS messages, contacts, location data, device accounts, and installed applications. The campaign is believed to be the work of a Hamas-affiliated actor known as Arid Viper. There are currently no details available on the scope of the campaign and whether any of the infections were successful. Acronis said it highlights how trusted emergency services can be weaponized during periods of geopolitical tension using social engineering. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-2796 (Mozilla Firefox), CVE-2026-21385 (Qualcomm), CVE-2026-2256 (MS-Agent), CVE-2026-26198 (Ormar), CVE-2026-27966 (langflow), CVE-2025–64712 (Unstructured.io), CVE-2026-24009 (Docling), CVE-2026-23600 (HPE AutoPass License Server), CVE-2026-27636, CVE-2026-28289 (aka Mail2Shell) (FreeScout), CVE-2025-67736 (FreePBX), CVE-2025-34288 (Nagios XI), CVE-2025-14500 (IceWarp), CVE-2026-20079 (Cisco Secure Firewall Management Center), CVE-2025-13476 (Viber app for Android), CVE-2026-3336, CVE-2026-3337, CVE-2026-3338 (Amazon AWS-LC), CVE-2026-25611 (MongoDB), CVE-2026-3536, CVE-2026-3537, CVE-2026-3538 (Google Chrome), CVE-2026-27970 (Angular), CVE-2026-29058 (AVideo) a privilege escalation flaw in IPVanish VPN for macOS (no CVE), and and a remote code execution vulnerability in Ghost CMS (no CVE). 🎥 Cybersecurity Webinars Automating Real-World Security Testing to Prove What Actually Works → Running a security test once a year and hoping for the best? That's not a strategy anymore. This webinar shows you how to continuously test your defenses using real attack techniques — so you actually know what holds up and what quietly breaks when no one's looking. When AI Agents Become Your New Attack Surface → AI tools aren't just answering questions anymore — they're browsing the web, hitting APIs, and touching your internal systems. That changes everything about how you think about risk. This webinar breaks down what that means for security, and what you actually need to do before something goes wrong. 📰 Around the Cyber World New AirSnitch Attack Shows Wi-Fi Client Isolation May Not Be Enough — A group of academics has developed a new attack called AirSnitch that breaks the encryption that separates Wi-Fi clients. Xin'an Zhou, the lead author of the research paper, told Ars Technica that AirSnitch bypasses worldwide Wi-Fi encryption and that it "might have the potential to enable advanced cyber attacks." The attack, at its core, leverages three weaknesses in client isolation implementations: (1) It abuses the group key(s) that are shared between all clients in the same Wi-Fi network, (2) It bypasses client isolation by tricking the gateway into forwarding packets to the victim at the IP layer by taking advantage of the fact that many networks only enforce client isolation at the MAC/Ethernet layer, and (3) It allows an adversary to manipulate internal switches and bridges to forward the victim's uplink and downlink traffic to the adversary. As a result, they enable the attacker to restore AitM capabilities even if client isolation protections exist. "We found that Wi-Fi client isolation can often be bypassed," Mathy Vanhoef said. "This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others." Google Tracked 90 Exploited 0-Days in 2025 — Google said it tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025, up from 78 in 2024 and down from 100 in 2023. "Both the raw number (43) and proportion (48%) of vulnerabilities impacting enterprise technologies reached all-time highs, accounting for almost 50% of total zero-days exploited in 2025," the company said. Of these, vulnerabilities in security and networking appliances made up about half (21) of the enterprise-related zero-days in 2025. Mobile zero-days rebounded from nine in 2024 to 15 in 2025, with commercial surveillance vendors (15, plus likely another three) leading the charge in exploiting zero-day vulnerabilities than state-sponsored cyber espionage groups (12) for the first time. The names of the commercial spyware companies were not disclosed. Microsoft had the largest number of actively exploited flaws at 25, followed by Google (11), Apple (8), Cisco (4), Fortinet (4), Ivanti (3), and Broadcom VMware (3). Memory safety issues accounted for 35% of all exploited zero-day vulnerabilities last year. Financially motivated threat groups, including ransomware gangs, also targeted enterprise technologies and accounted for nine zero-days in 2025, double the five attributed to them in 2024. Velvet Tempest Deploys ClickFix Attack — Velvet Tempest (aka DEV-0504) has been observed using a ClickFix lure, followed by hands-on-keyboard activity consistent with Termite ransomware tradecraft. According to a report by Deception.Pro, the attack used the social engineering technique to drop payloads like DonutLoader and CastleRAT. "Follow-on activity included Active Directory reconnaissance (domain trusts, server discovery, user listing) and attempted browser credential harvesting via a PowerShell script downloaded from 143.198.160[.]37," it said. "Telemetry and infrastructure in this chain align with a modern initial-access playbook: rapid staging, heavy use of living-off-the-land binaries (LOLBins), and long-lived command-and-control (C2) traffic that blends into normal browser noise." No ransomware was deployed in the attack that took place between February 3 and 16, 2026. Ghanaian National Pleads Guilty to Role in $100M Romance Scam — A Ghanaian national pleaded guilty to his role in a massive fraud ring that stole over $100 million from victims across the U.S. through business email compromise attacks and romance scams. 40-year-old Derrick Van Yeboah pleaded guilty to conspiracy to commit wire fraud and agreed to pay more than $10 million in restitution. "Van Yeboah personally perpetrated many of the romance scams by impersonating fake romantic partners in communications with victims," the U.S. Justice Department said. "Many of the conspiracy’s victims were vulnerable older men and women who were tricked into believing that they were in online romantic relationships with persons who were, in fact, fake identities assumed by members of the conspiracy." The conspirators, part of a criminal organization primarily based in Ghana, also committed business email compromises to deceive businesses into wiring funds to the enterprise. In total, the scheme stole and laundered more than $100 million from dozens of victims. After stealing the money, the fraud proceeds were laundered to West Africa. The defendant is scheduled to be sentenced in June 2026. Taiwan Indicts 62 People for Cyber Scams — Prosecutors in Taipei indicted 62 people and 13 companies for their involvement in cyber scam operations organized throughout Asia by the Prince Group. Chen Zhi, the founder of the Prince Group, was indicted by U.S. prosecutors last year on money laundering charges. Taipei prosecutors said those associated with Prince Group laundered at least $339 million into Taiwan and used the stolen funds to buy 24 properties, 35 vehicles, and other assets amounting to approximately $1.7 million. In all, authorities seized about $174 million in cash and assets. Prince Group "effectively controlled 250 offshore companies in 18 countries, holding 453 domestic and international financial accounts. By creating fictitious transaction contracts between these offshore companies, the group laundered money through foreign exchange channels," they added. Ransomware Actors Use AzCopy — Ransomware operators are ditching the usual tools like Rclone for Microsoft's own AzCopy, turning a trusted Azure utility into a stealthy data exfiltration mechanism and blending into normal activity. "The adoption of AzCopy and other familiar tools by attackers represents a similar logic to living-off-the-land in the final and most critical phase of an operation: exfiltrating data out of an organization," Varonis said. "Spinning up an Azure storage account takes minutes and requires only a credit card or compromised credentials. The attacker gains the benefits of Microsoft's global infrastructure while security teams struggle to distinguish between malicious uploads and legitimate traffic." Threat Actors Exploit Critical Flaw in WPEverest Plugin — Threat actors are exploiting a critical security flaw in WPEverest's User Registration & Membership plugin (CVE-2026-1492, CVSS score: 9.8) to create rogue administrator accounts. The vulnerability affects all versions of User Registration & Membership through 5.1.2. The issue has been addressed in version 5.1.3. Wordfence said the plugin is susceptible to improper privilege management, which enables the creation of bogus admin accounts. "This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist," it said. "This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration." MuddyWater Evolves Its Tactics — The Iranian hacking group known as MuddyWater has been observed leveraging Shodan and Nuclei to identify potential vulnerable targets, as well as using subfinder and ffuf to perform enumeration of target web applications. The findings come from an analysis of the threat actor's VPS server hosted in the Netherlands. MuddyWater is also said to be attempting to scan and/or exploit recently disclosed CVEs related to BeyondTrust (CVE-2026-1731), Ivanti (CVE-2026-1281), n8n (CVE-2025-68613), React (CVE-2025-55182), SmarterMail (CVE-2025-52691), Laravel Livewire (CVE-2025-54068), N-Central (CVE-2025-9316), Citrix NetScaler (CVE-2025-5777), Langflow (CVE-2025-34291), and Fortinet (CVE-2024-55591, CVE-2024-23113, CVE-2022-42475), along with SQL injection vulnerabilities in BaSalam and an unspecified Postgres development platform for initial access. One of the custom tools identified in the server is KeyC2, a command-and-control (C2) framework that allows operators to remotely control compromised Windows machines over a custom binary protocol on port 1269 from a Python script. Two C2 tools used by the adversary are PersianC2, which relies on standard HTTP polling to receive commands and files via JSON API endpoints, and ArenaC2, a Python-based program that operates over HTTP POST requests. Also detected is a PowerShell loader that leads to the execution of obfuscated Node.js payloads that appear similar to Tsundere Botnet. The infrastructure is assessed to have been used to target entities in Israel, Egypt, Jordan, the U.A.E., and the U.S. Some aspects of the activity overlap with Operation Olalampo. 2,622 Valid Certificates Exposed — A new study undertaken by Google and GitGuardian found over a million unique private keys leaked across GitHub and Docker Hub, out of which 40,000 were mapped to 140,000 real TLS certificates. "As of September 2025, 2,600 of these certificates were valid, with more than 900 actively protecting Fortune 500 companies, healthcare providers, and government agencies," GitGuardian said. "Our disclosure campaign achieved 97% remediation, but at the cost of 4,300 emails sent, 1,706 entities contacted, 9 bug bounty submissions, countless follow-ups, and days of meticulous attribution work employing multiple OSINT techniques. The high success rate masks the extraordinary effort required to protect organizations that fail to protect themselves." Context7 MCP Server Suffers from ContextCrush — A critical security flaw in Upstash's Context7 MCP Server, a widely used tool for delivering documentation to AI coding assistants, has been discovered. Dubbed ContextCrush, the vulnerability could allow attackers to inject malicious instructions into AI development tools through a trusted documentation channel. Noma Security, which disclosed details of the flaw, said it's rooted within the platform's "Custom Rules" feature, which allows library maintainers to provide AI-specific instructions to help assistants better interpret documentation. "Context7 operates both as the registry, where anyone can publish and manage library documentation, and as the trusted delivery mechanism that pushes content directly into the AI agent's context," security researcher Eli Ainhorn said. "The attacker never needs to reach the victim's machine. Instead, the attacker can plant malicious custom rules in Context7's registry, and Context7’s infrastructure delivers them through the MCP server to the AI agent running in the developer's IDE. As agents are execution machines and run whatever is loaded into their context, all the victim’s agent does is execute the attacker's instructions on the victim’s machine, using its own tool access (Bash, file read/write, network). In this scenario, the agent has no way to distinguish between legitimate documentation and attacker-controlled content because they arrive through the same trusted channel and from the same trusted source." German Court Sentences Key Person Behind Call Center Scam — A German court has sentenced a suspected central figure in the so-called Milton Group call-center fraud network to seven-and-a-half years in prison. Although the court did not publicly name the defendant, court records reviewed by the Organized Crime and Corruption Reporting Project (OCCRP) indicate the person convicted was Mikheil Biniashvili, a citizen of Georgia and Israel. In addition to the prison sentence, the court ordered the confiscation of €2.4 million ($2.8 million) linked to the operation. Between 2017 and 2019, the defendant ran a call-center operation in Albania that used trained agents to persuade victims to invest in fraudulent online trading schemes. The scheme caused losses of about €8 million ($9.4 million) to victims, mostly in German-speaking countries. The operation employed up to 600 people at its peak. Call-center agents allegedly posed as investment advisers, building trust with targets before persuading them to deposit funds into fake trading platforms controlled by the network by promising large investment returns. Biniashvili was arrested in Armenia in 2023 and extradited to Germany in 2024. Multiple Flaws in Avira Internet Security — Three vulnerabilities have been disclosed in Avira Internet Security that could allow for arbitrary file deletion (CVE-2026-27748) in the Software Updater component, an insecure deserialization (CVE-2026-27749) in System Speedup, and an arbitrary folder deletion over TOCTOU (CVE-2026-27748) in the Optimizer. "The file delete primitive is useful on its own," Quarkslab said. "The other two both result in Local Privilege Escalation to SYSTEM." Russian Ransomware Operator Pleads Guilty in U.S. — Evgenii Ptitsyn, a 43-year-old Russian national, has pleaded guilty in a U.S. court to running the Phobos ransomware outfit that targeted more than 1,000 victims globally and extorted ransom payments worth over $39 million. Ptitsyn was extradited from South Korea in November 2024. "Beginning in at least November 2020, Ptitsyn and others conspired to engage in an international computer hacking and extortion scheme that victimized public and private entities through the deployment of Phobos ransomware," the Justice Department said. "As part of the scheme, Ptitsyn and his co-conspirators developed and offered access to Phobos ransomware to other criminals or 'affiliates' to encrypt victims' data and extort ransom payments from victims. The administrators operated a darknet website to coordinate the sale and distribution of Phobos ransomware to co-conspirators and used online monikers to advertise their services on criminal forums and messaging platforms." Ptitsyn faces a maximum penalty of 20 years in prison for wire fraud charges. Fake Google Security Check Leads to RAT — A bogus website resembling the Google Account security page is being used to deliver a Progressive Web App (PWA) capable of harvesting one-time passcodes and cryptocurrency wallet addresses, and proxying attacker traffic through victims' browsers. "Disguised as a routine security checkup, it walks victims through a four-step flow that grants the attacker push notification access, the device's contact list, real-time GPS location, and clipboard contents – all without installing a traditional app," Malwarebytes said. "For victims who follow every prompt, the site also delivers an Android companion package introducing a native implant that includes a custom keyboard (enabling keystroke capture), accessibility-based screen reading capabilities, and permissions consistent with call log access and microphone recording." Phishing Campaign Abuses Google Infrastructure — A new email phishing campaign is leveraging legitimate Google infrastructure to bypass standard security filters. The activity uses Google Cloud Storage (GCS) to host initial phishing URLs that, when clicked, redirect unsuspecting users to a malicious site designed to capture their financial information or deploy malware. "By hosting the initial link on Google's servers, the attackers ensure the email passes authentication checks like SPF and DKIM," security researcher Anurag Gawande said. Client-Side Injection Conducts Ad Fraud — A new malicious client-side injection originating from a malicious browser extension impersonating Microsoft Clarity has been found to overwrite referral tokens to redirect affiliate revenue to unknown threat actors. "A browser extension is injecting obfuscated JavaScript from msclairty[.]com, a typosquatted domain impersonating Microsoft Clarity," c/side's Simon Wijckmans said. "The domain is not serving analytics. It is delivering an obfuscated JavaScript payload that performs affiliate cookie stuffing, tracking cookie deletion, and Fetch API hijacking inside the visitor's browser. This prevents a competing tracking service from recording the real traffic source. The attacker does not just want credit for the visit. They actively block other trackers from capturing any attribution data that would conflict with their fraudulent cookie." The script has affected sites across multiple unrelated sectors, including transportation, SaaS platforms, sports management, and government payment portals. Impacted visitors primarily span Chrome versions 132, 138, and 145, and originate from U.S.-based IP addresses on the East and West coasts. Illinois Man Charged with Hacking Snapchat Accounts to Steal Nudes — U.S. prosecutors have charged a 26-year-old Illinois man, Kyle Svara, with conducting a phishing operation that made it possible to break into the Snapchat accounts of approximately 570 women to steal private photos and sell them online. "From at least May 2020 to February 2021, Svara used social engineering and other resources to collect his targets' emails, phone numbers, and/or Snapchat usernames," the Justice Department said. "He then used those means of identification to access his targets' Snapchat accounts, which prompted Snap Inc. to send account security codes to those women. Using anonymized phone numbers, Svara posed as a representative of Snap Inc. and sent more than 4,500 text messages to hundreds of women, requesting those Snapchat access codes." Svara is alleged to have accessed the Snapchat accounts of at least 59 women without permission to download their nude or semi-nude images and sell them on internet forums. Meta Sued Over AI Smart Glasses' Privacy Concerns — Meta is facing a new class action lawsuit over its AI-powered Ray-Ban Meta glasses, following a report from Swedish newspapers Svenska Dagbladet and Goteborgs-Posten that employees at Kenya-based subcontractor Sama are reviewing intimate, personal footage filmed from customers' glasses. Meta said subcontracted workers might sometimes review content captured by its AI smart glasses for the purpose of improving the "experience," as stated in its Privacy Policy. It also claimed that data is filtered to protect people's privacy. But the investigation found that this step did not always consistently work. "Unless users choose to share media they've captured with Meta or others, that media stays on the user's device," Meta told BBC News. "When people share content with Meta AI, we sometimes use contractors to review this data for the purpose of improving people's experience, as many other companies do." Total Ransomware Payments Stagnated in 2025 — The total ransomware payments in 2025 stagnated, even if the number of attacks increased. According to blockchain analysis firm Chainalysis, total on-chain ransomware payments fell by approximately 8% to $820 million in 2025, even as claimed attacks rose 50%. "While aggregate revenue stagnated, the median ransom payment grew 368% year-over-year to nearly $60,000," the company said. "The 2025 total is likely to approach or exceed $900 million as we attribute more events and payments, just as our 2024 total grew from our initial $813 million estimate this time last year." The decline in payment rates from 63% in 2024 to just 29% last year indicates that fewer victims are yielding to attackers' ransom demands, it added. The development comes amid increased fragmentation of the ransomware ecosystem and threat actors shifting towards more stealthy methods, such as defense evasion and persistence techniques, to prioritize data theft and prolonged, low-noise access. Mobile Blockchain Wallet Found Vulnerable to Severe Flaws — An unnamed mobile blockchain wallet app for Android has been found susceptible to two independent severe vulnerabilities, allowing untrusted deep links to trigger sensitive wallet flows and trick users into approving phishing-driven transactions, as well as retain cryptographic private keys from the device despite deleting an account. This meant that an attacker with later device access could re-import the account using its public address and regain full signing authority without re-entering the keys. According to LucidBit Labs, the vulnerabilities have been patched by the developer. "The main strength of crypto wallets lies in their cryptographic foundations," security researcher Assaf Morag said. "However, when these wallets are implemented as user-facing applications, the overall orchestration of the system becomes just as critical as the cryptography itself. As the saying goes, a system’s security posture is defined by its weakest link. In this case, the two vulnerabilities demonstrate how flaws at the application layer can undermine the entire security model, despite the strength of the underlying cryptography." Kubernetes RCE Via Nodes/Proxy GET Permission — New research has identified an authorization bypass in Kubernetes Role-based access control (RBAC) that allows a service account with nodes/proxy GET permissions to execute commands in any Pod in the cluster. The issue exploits a bug in how Kubernetes API servers handle WebSocket connections. "Nodes/proxy GET allows command execution when using a connection protocol such as WebSockets," security researcher Graham Helton said. "This is due to the Kubelet making authorization decisions based on the initial WebSocket handshake's request without verifying CREATE permissions are present for the Kubelet's /exec endpoint, requiring different permissions depending solely on the connection protocol. The result is anyone with access to a service account assigned nodes/proxy GET that can reach a Node's Kubelet on port 10250 can send information to the /exec endpoint, executing commands in any Pod, including privileged system Pods, potentially leading to a full cluster compromise." The Kubernetes project has declined to address the issue, stating its intended behavior. However, it's expected to release Fine-Grained Kubelet API Authorization (KEP-2862) next month to address the attack. "A targeted patch would require coordinated changes across multiple components with special-case logic," Edera said. "This is the kind of complexity that could lead to future vulnerabilities. Once KEP-2862 reaches GA and sees adoption, nodes/proxy can be deprecated for monitoring use cases." Other Key Stories on the Radar — The Israeli government is working on the country's first cybersecurity law, the U.S. National Security Agency (NSA) published Zero Trust Implementation Guidelines (ZIGs) to help organizations safeguard sensitive data, systems, and services against sophisticated cyber threats, Google Project Zero found multiple vulnerabilities that could be used to bypass a new Windows 11 feature called Administrator Protection and obtain admin privileges, threat actors are continuing to abuse Microsoft Teams functionality by leveraging guest invitations and phishing-themed team names to impersonate billing and subscription notifications, and a loader named PhantomVAI has been used in the wild over the past year to deploy other payloads, such as Remcos RAT, XWorm, AsyncRAT, DarkCloud, and SmokeLoader. 🔧 Cybersecurity Tools DetectFlow → It is an open-source detection pipeline from SOC Prime that matches streaming log events against Sigma rules in real time — before they ever reach your SIEM. Instead of relying on your SIEM to do the heavy lifting, it tags and enriches events in-flight using Apache Kafka and Flink, then passes the results downstream to wherever you need them. Built on 11 years of detection intelligence, it's designed for teams who want faster detection, more rule coverage, and less dependency on SIEM-imposed limits. ADTrapper → It is an open-source platform that analyzes Windows Active Directory authentication logs and flags threats using 54+ built-in detection rules — covering everything from brute force to AD CS attacks. It runs in Docker, deploys with one command, and supports SharpHound data for deeper AD analysis. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's your week. A lot happened. Some of it was bad, some of it was worse, and a little bit of it was actually good. The scoreboard is messy, like it always is. Same time next week — and if history is any guide, we'll have plenty more to talk about. Stay patched, stay skeptical, and maybe don't click that link.
thehackernews.comMar 9, 2026extracted
Week in review: Weaponized OAuth redirection logic delivers malware, Patch Tuesday forecast
Week in review: Weaponized OAuth redirection logic delivers malware, Patch Tuesday forecast Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: BlacksmithAI: Open-source AI-powered penetration testing framework BlacksmithAI is an open-source penetration testing framework that uses multiple AI agents to execute different stages of a security assessment lifecycle. BlacksmithAI runs as a hierarchical system in which an orchestrator coordinates task execution across specialized agents. Security debt is becoming a governance issue for CISOs Application security backlogs keep expanding across large development portfolios. Veracode’s 2026 State of Software Security Report puts numbers behind a familiar operational pattern, fixes lag discovery, and older weaknesses stay open across release cycles. Your dependencies are 278 days out of date and your pipelines aren’t protected Applications continue to ship with known weaknesses even as development workflows speed up. A new Datadog State of DevSecOps 2026 report examines how dependency management and pipeline practices are influencing exposure across cloud native environments. AI went from assistant to autonomous actor and security never caught up Enterprise AI deployments have shifted from pilot programs to production systems handling customer data, executing business transactions, and integrating with core infrastructure. That has exposed a significant gap between what AI agents can do and what security teams can observe or control. Cybersecurity is now the price of admission for industrial AI Industrial organizations are accelerating AI deployment across manufacturing, utilities, and transportation and running straight into a security problem. Cisco’s 2026 State of Industrial AI Report, based on responses from more than 1,000 decision-makers across 19 countries, finds that cybersecurity has become the single largest obstacle to AI adoption, outranking skills gaps, integration challenges, and budget constraints. Cybersecurity professionals are burning out on extra hours every week Cybersecurity professionals in the U.S. are working an average of 10.8 extra hours per week beyond their contracted schedules, according to survey data collected from 300 cybersecurity and IT leaders by Sapio Research. That figure effectively adds a sixth working day to the standard week for a large portion of the field. Nearly half of respondents reported working 11 or more overtime hours weekly, and one in five logged more than 16 additional hours. The vulnerability that turns your AI agent against you Zenity Labs disclosed PleaseFix, a family of critical vulnerabilities affecting agentic browsers, including Perplexity Comet, that allow attackers to hijack AI agents, access local files, and steal credentials within authenticated user sessions. The vulnerabilities can be triggered through malicious content embedded in routine workflows, enabling unauthorized actions without user awareness. Threat actors weaponize OAuth redirection logic to deliver malware An ongoing phishing campaign is abusing the OAuth authentication redirection mechanism to avoid triggering conventional email and browser defenses, Microsoft researchers have revealed. The attackers are targeting government and public-sector organizations, and redirecting unsuspecting users from trusted login pages to their own infrastructure, to serve malware or capture login credentials. Coruna: Spy-grade iOS exploit kit powering financial crime A powerful iOS exploit kit has circulated among multiple threat actors over the past year, moving from a commercial surveillance operation to state-linked espionage campaigns and, ultimately, ended into the hands of financially motivated hackers, according to new research from Google’s Threat Intelligence Group (GTIG). Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500) A critical RCE vulnerability (CVE-2025-14500) in IceWarp, an EU-made business communication and collaboration platform, may be exploited by attackers to gain unauthorized access to exposed unpatched servers. According to the Shadowserver Foundation, there are currently over 1,200 internet-facing instances that have yet to receive a fix, and the organization is sending out alerts to the owners, urging them to update. As AI agents start making purchases, security teams must rethink risk In this Help Net Security interview, Donald Kossmann, CTO at fintech company Chargebacks911, talks about the emerging security, fraud, and governance risks of “agentic commerce,” where AI agents can autonomously make purchasing decisions on behalf of users or organizations. FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) A newly discovered vulnerability (CVE-2026-28289) in the open-source help desk platform FreeScout could allow attackers to take over vulnerable servers by sending a specially crafted email to a FreeScout mailbox. FreeScout is a free, open-source help desk and shared inbox system used by businesses or teams to manage customer support conversations in one place. Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities Cisco has confirmed that two Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128 and CVE-2026-20122) patched in late February 2025 are being exploited by attackers. CVE-2026-20128 is a bug in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which could allow an authenticated, local attacker to gain DCA user privileges on an affected system. Iran-linked APT targets US critical sectors with new backdoors An Iran-linked hacking group has been active inside the networks of several US organizations since early February, raising concerns that the activity could precede broader cyber operations connected to escalating geopolitical tensions in the Middle East. Why workforce identity is still a vulnerability, and what to do about it Most organizations believe they have workforce identity under control. New hires are verified. Accounts are provisioned. Multi-factor authentication is enforced. Audits are passed. Then a breach happens, often through an account that was “properly secured.” But the problem can be traced back to the fact that identity verification, provisioning, authentication, and recovery operate as separate events, not a continuous system of trust. Engineering trust: A security blueprint for autonomous AI agents AI agents have evolved from just chatbots, answering questions to executing actions using various integrated tools, often autonomously, and as such the traditional security models have become less efficient. A single malicious instruction hidden in a webpage (that the agent processes), can manipulate that agent into performing unintended actions or leaking sensitive data. March 2026 Patch Tuesday forecast: Is AI security an oxymoron? Developers and analysts are using more AI tools to produce code and to test both the performance and security of the finished products. They are also embedding AI functionality in their products directly. But just how secure are these AI tools and routines themselves? Recent reports show they suffer from vulnerabilities just like any other code. When cyber threats start thinking for themselves In this Help Net Security video, Jason Rivera, Field CISO & Head of Solution Engineering at SimSpace, discusses how autonomous AI agents are changing cyber threats. Drawing on experience in the US Army, NSA, Deloitte, and CrowdStrike, he describes how security teams have traditionally measured risk through volume, speed, and sophistication. Why phishing still works today In this Help Net Security video, Gal Livschitz, Senior Penetration Tester at Terra Security, explains how phishing has evolved and why employees still fall for it. He outlines how phishing now uses HTTPS, branded pages, and lookalike domains, making attacks harder to spot. He highlights communication overload as a key weakness that attackers exploit. Motorola turns to GrapheneOS for smartphone security upgrade Motorola is strengthening smartphone security through a long-term partnership with the GrapheneOS Foundation, a mobile security nonprofit that develops a hardened operating system based on the Android Open Source Project. Anthropic’s Claude hit by widespread service outage (updated) Anthropic suffered widespread service disruptions Monday morning, leaving thousands of users unable to access its Claude AI platform. Most users reporting problems said they encountered errors when attempting to log in. Meta AI in WhatsApp organizes chats and reopens privacy issues The trend of integrating AI into digital platforms continues. In the latest Android beta release (2.26.9.4), the company has introduced a feature that allows users to organize their chat history with the help of Meta AI. Anthropic poaches users from rival chatbots with easier migration The controversy over Anthropic’s negotiations with the Pentagon has driven increased interest in Claude. Negotiations between the Department of Defense and Anthropic collapsed after a deadline for an agreement expired without a deal. The Pentagon had pressed the company to loosen certain restrictions on how its AI systems could be used. Anthropic declined and kept its existing policy limits in place. $100 radio equipment can track cars through their tire sensors When people consider what might track their movements, they think of smartphone apps, GPS services, or roadside cameras. The tires of a new car rarely enter that equation. Researchers at IMDEA Networks Institute, together with European partners, found that Tire Pressure Monitoring System (TPMS) sensors inside each wheel broadcast unencrypted wireless signals containing persistent identifiers. Google speeds up Chrome updates with new security-focused release cycle The Chrome browser is moving to a two-week release cycle, a change intended to give developers and users faster access to new features, performance improvements and bug fixes. The new schedule begins with the stable release of Chrome 153 on September 8, 2026, followed by new beta and stable releases every two weeks. The change applies to desktop, Android and iOS platforms, while the Dev and Canary channels remain unchanged. Workers reviewing Meta Ray-Ban footage encounter users’ intimate moments Bank details and intimate moments captured without people realizing they are being recorded are the new privacy nightmare behind the latest tech fashion hit, Meta Ray-Ban smart glasses. A joint investigation by Svenska Dagbladet and Göteborgs-Posten found that footage and audio recorded by Meta’s Ray-Ban smart glasses are reviewed by human contractors in Kenya, including recordings containing sensitive personal material. Authorities pull plug on Tycoon 2FA phishing-as-a-service platform Tycoon 2FA, a phishing-as-a-service platform that allowed cybercriminals to bypass MFA and break into online accounts, has been disrupted by law enforcement agencies and cybersecurity partners. Western governments lay the groundwork for secure 6G networks Governments are preparing for 6G, the next generation of mobile networks, placing security and resilience among their top priorities. In response, seven countries participating in the Global Coalition on Telecoms (GCOT) have introduced a set of 6G Security and Resilience Principles, developed with support from industry partners. Backup strategies are working, and ransomware gangs are responding with data theft Business email compromise (BEC) and funds transfer fraud combined for 58% of all cyber insurance claims filed in 2025, according to data from Coalition covering more than 100,000 policyholders across the United States, Canada, the United Kingdom, Australia, and Germany. OpenAI’s GPT-5.4 doubles down on safety as competition heats up In the midst of recent developments and controversies surrounding a contract with the U.S. Department of Defense, OpenAI released the GPT-5.4 model. The release comes at a time when users are reportedly leaving ChatGPT for rival chatbots, particularly Anthropic’s Claude. Microsoft working on Teams feature to keep unauthorized bots at bay Microsoft plans to add a new Teams feature that lets meeting admins identify and control third-party bots before they join. According to the Microsoft 365 Roadmap, the feature is scheduled to begin rolling out in May 2026 on Desktop, Mac, Linux, iOS, and Android versions of Microsoft Teams. AI risk moves into the security budget spotlight Enterprises are pushing AI deeper into workflows that touch sensitive data across cloud platforms and SaaS apps. The 2026 Thales Data Threat Report, based on a survey of 3,120 respondents in 20 countries, places that shift alongside growing pressure on data protection, identity controls, and cloud security. UK reduces cyberattack fix times from two months to eight days The UK government has launched a new vulnerability monitoring service (VMS) that promises to reduce the time needed to fix critical cyber weaknesses across the public sector. The service, launched as part of the Blueprint for Modern Digital Government, published in January 2025, continuously scans internet-facing systems at around 6,000 public sector organizations. Using commercial and proprietary tools, it detects about 1,000 types of cyber vulnerabilities. IPFire ships its 200th core update with a new domain blocklist and kernel upgrade Network firewall distribution IPFire released Core Update 200, marking the 200th incremental update to the 2.29 branch. The release bundles a kernel upgrade, a beta domain blocklist service, security patches for OpenSSL and glibc, and a range of component updates. 5 years of shifting cybersecurity behavior Online security is built through routine decisions made across devices and accounts. People choose how to create passwords, how often to reuse them, and how much effort to invest in protecting personal data. The National Cybersecurity Alliance and CybSafe’s Oh, Behave! The Cybersecurity Attitudes and Behaviors Report: 2021–2025 follows those patterns over five years, drawing on responses from more than 24,000 adults and documenting how attitudes and behaviors shift over time. Healthcare organizations are accepting cyber risk to cut costs Healthcare organizations are cutting cybersecurity budgets under financial pressure even as the threats targeting their systems intensify. A PwC survey of 381 global healthcare executives, conducted between May and July 2025, puts numbers to the gap between the risks the sector faces and the controls it has in place. Android’s March 2026 security patch fixes over 100 flaws, one under targeted exploitation The Android March 2026 security patch addresses vulnerabilities across dozens of components and includes one CVE confirmed under active exploitation. Devices running a patch level of 2026-03-05 or later receive fixes for all disclosed issues. New Defender deployment tool streamlines Windows device onboarding with single executable Microsoft’s Defender deployment tool for Windows helps administrators manage device onboarding at scale with updated progress visibility and additional controls. Cloudflare tracked 230 billion daily threats and here is what it found Cloudflare’s network blocks over 230 billion threats per day. The volume indicates how routine and automated the attack cycle has become, and the patterns behind that volume point to a shift in how breaches begin and progress. Cloudflare’s threat research unit, Cloudforce One, published its inaugural cyber threat report 2026, covering activity observed through 2025 and projecting into the year ahead. The report draws on telemetry from Cloudflare’s network, which handles roughly 20% of global web traffic. Immutable Linux distribution Nitrux 6.0.0 adds GPU passthrough, boot-level recovery, C++ update system Nitrux 6.0.0, released March 3, 2026, packages several components that security practitioners running Linux workstations will find worth examining: a new hypervisor orchestrator with IOMMU-enforced isolation, a rewritten update system with cryptographic verification, and a recovery mechanism that operates from within the boot process itself. LeakBase cybercrime forum with 142,000 users taken down in global operation LeakBase, an open-web cybercrime forum facilitating the trade of leaked databases and “stealer logs” containing stolen credentials, has been taken down in an international law enforcement operation coordinated by Europol and involving authorities from 14 countries. Google changes Play Store policies after settling Epic Games dispute Google is making changes to the Play Store after settling its legal fight with Epic Games, focusing on three areas: more billing options, lower fees with new programs for developers, and a program for registered app stores. That attractive online ad might be a malware trap Malware increasingly travels through the infrastructure that delivers online advertising. The Media Trust’s Global Report on Digital Trust, Ad Integrity, and the Protection of People describes a digital ad ecosystem where scam campaigns, malicious redirects, and malware delivery appear alongside marketing traffic. What happens when AI teams compete against human hackers A cybersecurity competition produced what may be the largest controlled dataset comparing AI-augmented teams to human-only teams on professional-grade offensive security tasks. The event, called NeuroGrid, ran for 72 hours on the Hack The Box platform and drew 1,337 registered human-only teams and 156 registered AI-agent teams competing across 36 challenges in nine security domains at four difficulty levels. Cursor Automations turns code review and ops into background tasks Cursor Automations, the always-on agent platform from Cursor, is expanding with a new generation of autonomous systems that streamline code review, incident response, and other engineering workflows. The platform runs AI agents on schedules or in response to development events. New cyber module strengthens risk planning for health organizations The Administration for Strategic Preparedness and Response’s (ASPR) new cybersecurity module in the Risk Identification and Site Criticality (RISC) 2.0 Toolkit helps organizations identify critical gaps, prioritize investments, and make informed decisions about risk mitigation to reduce disruptions to patient care and strengthen resilience. Secure by Design: Building security in at the beginning Secure by Design is not a single tool, product, or one‑time activity. It is a holistic approach that requires security to be deliberately embedded from the very beginning, at the point where systems, software, and services are conceived and designed. Rather than reacting to vulnerabilities after deployment, Secure by Design emphasizes anticipating risk early and addressing it through intentional design decisions, clearly defined security requirements, and accountability across the entire lifecycle. Webinar: The True State of Security 2026 In the webinar The True State of Security 2026, you’ll gain insight into why AI is distracting teams from more persistent risks and how human access and permissions remain the weakest link. You’ll also learn why current security workflows are slowing organizational growth and what a balanced security strategy should look like heading into 2026. Cybersecurity jobs available right now: March 3, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: March 6, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Beazley Security, Push Security, Samsung, and Tufin.
helpnetsecurity.comMar 8, 2026extracted
Workers reviewing Meta Ray-Ban footage encounter users’ intimate moments
Workers reviewing Meta Ray-Ban footage encounter users’ intimate moments Bank details and intimate moments captured without people realizing they are being recorded are the new privacy nightmare behind the latest tech fashion hit, Meta Ray-Ban smart glasses. A joint investigation by Svenska Dagbladet and Göteborgs-Posten found that footage and audio recorded by Meta’s Ray-Ban smart glasses are reviewed by human contractors in Kenya, including recordings containing sensitive personal material. A contractor workforce in Nairobi A troubling reality for tech giants is that a large part of the AI revolution is built on the labor of workers in poorer countries. The investigation focused on Sama, a Meta subcontractor in Nairobi, Kenya, employing manual laborers known as data annotators who train AI systems by labeling images, video, and speech. Thousands of workers are involved in this type of AI training work. Tasks include drawing bounding boxes, assigning object labels, checking transcriptions, and performing quality assurance to help systems interpret visual scenes and user queries. Journalists interviewed more than thirty Sama employees at different levels. All spoke on condition of anonymity for fear of reprisals. Interviewees described repeated exposure to highly sensitive clips. Examples include bathroom visits, people undressing, sex, pornography viewed while wearing the glasses, and bank cards visible in recordings. Some workers described seeing material that could trigger enormous scandals if leaked. According to workers, the facility operates under strict security controls, including office cameras and restrictions on bringing recording-capable devices into the building to prevent leaks. “You understand that it is someone’s private life you are looking at, but at the same time you are just expected to carry out the work. You are not supposed to question it. If you start asking questions, you are gone,” one worker said. Former Meta employees said faces appearing in annotation data are automatically blurred. Data annotators in Kenya, however, told that the anonymisation does not always work as intended, with faces sometimes remaining visible in the material they review. Asked how this can happen, one former Meta employee said the algorithms sometimes miss, particularly in difficult lighting conditions when certain faces and bodies become visible. Unanswered questions about where the footage goes Journalists repeatedly asked Meta where the images reviewed by contractors originate and whether private recordings made in countries such as Sweden could end up being viewed by workers abroad. They also asked how users are informed about the glasses, what safeguards exist to prevent sensitive material from reaching annotators, how subcontractors are audited, and how long voice and video recordings are stored. After two months, Meta responded with a written statement from a spokesperson in London. The company did not directly address the questions, instead describing how data moves from the glasses to the user’s mobile app and referring to its AI terms of use and privacy policy. Those policies note that content may be subject to human review. They do not specify where such reviews take place. Lack of knowledge in stores To assess how much eyewear store employees know about the data practices of Meta Ray-Ban smart glasses, journalists visited ten eyewear store in Sweden. In several cases, employees did not know what data the glasses transmit, where the information is sent, whether anything is automatically shared with Meta, or how users’ voice and video recordings are processed. Staff in different stores also provided contradictory answers, and many said they believed all data remains locally in the app. Tests carried out during the investigation found that this was not the case. Sales staff’s lack of knowledge means customers may receive incomplete or incorrect information and remain unaware of the risks to their personal data.
helpnetsecurity.comMar 5, 2026extracted
Android app uses Bluetooth signals to detect nearby smart glasses
Android app uses Bluetooth signals to detect nearby smart glasses Smart glasses with built-in cameras are showing up in more public spaces, and a growing number of people want a way to know when one is nearby. An Android app called Nearby Glasses, developed by Yves Jeanrenaud, attempts to fill that gap by scanning Bluetooth Low Energy traffic for manufacturer identifiers associated with known smart glasses makers. The project cites several reported incidents that motivated its development, including documented cases of Meta Ray-Ban glasses being used to record people without consent and at least one case where a Harvard student demonstrated real-time facial recognition using the glasses paired with publicly available data. How detection works Nearby Glasses does not rely on device names or UUIDs, both of which are inconsistent across BLE advertising frames. It targets the manufacturer-specific data field in BLE advertising packets, specifically the company ID field assigned by the Bluetooth Special Interest Group. These identifiers are standardized, mandatory, and immutable within the BLE spec, which makes them a more stable detection signal than other parts of the advertising frame. The app currently monitors for four company IDs: 0x01AB for Meta Platforms, 0x058E for Meta Platforms Technologies, 0x0D53 for Luxottica (the manufacturer of Meta Ray-Ban glasses), and 0x03C2 for Snapchat, maker of Snap Spectacles. Users can override the built-in list and enter custom hex values through the settings menu, which lets the app trigger on any manufacturer ID the user specifies. The app runs as an Android foreground service to maintain scan persistence. When a BLE device matching one of the monitored company IDs is detected at or above a configurable RSSI threshold, the app pushes a local notification. The default threshold is -75 dBm, which corresponds roughly to 10 to 15 meters in open space and 3 to 10 meters indoors. False positives are a known limitation Because the detection method targets company IDs shared across an entire manufacturer’s product line, the app will also trigger on other Bluetooth-enabled products from the same companies, including VR headsets. The project documentation acknowledges this openly. Jeanrenaud notes that contextual awareness matters: if there are no VR setups visible nearby, a match is more likely to correspond to wearable glasses. The notification cooldown is set to 10 seconds by default, which limits alert fatigue while keeping the user informed. RSSI thresholds and cooldown intervals are both adjustable in settings. Data handling and privacy The app collects no user data, sends no telemetry, and displays no ads. An optional exportable log records only BLE manufacturer ID codes encountered during a scan session. The log is stored locally and is not transmitted anywhere automatically. The project’s privacy documentation states that installing through Google Play may result in Google collecting install statistics, but the app itself has no data collection functionality. Detection gaps and roadmap The project documentation acknowledges that BLE scanning on Android does not always behave predictably. Signal absorption from human bodies, obstacles, and device orientation all affect RSSI readings, which means nearby devices may go undetected in some conditions. The documentation also notes that smart glasses users who intend covert recording typically pair devices in advance, so the pairing-phase device name broadcast, another potential detection vector, is rarely visible in the field. Jeanrenaud has listed several items for future development. These include expanding the monitored company ID list beyond Meta and Snap, a layout fix for Google Pixel devices where the menu overlaps the status bar, localization support by moving hardcoded text into Android’s strings resource files, and a potential iOS port contingent on access to Apple’s developer toolchain. A longer-term possibility noted in the project is deeper BLE traffic analysis through packet sniffing, which could reduce false positives by applying heuristics to encrypted transmissions. Jeanrenaud has stated that implementing this would require contributor involvement given the technical depth involved. The app is available on Google Play and as a direct APK download from GitHub. The source code is written in Kotlin and is publicly accessible in the project repository.
helpnetsecurity.comFeb 27, 2026extracted
Developer creates app to detect nearby smart glasses
An independent developer, moved after reading about the abuse of smart glasses to film people without their consent, decided to create an app to detect nearby smart glasses. Smart glasses are wearable devices built into ordinary-looking eyewear that add functions like audio, cameras, sensors, and sometimes a small display. They can let you listen to music, take calls, capture photos or video from your point of view, or see simple information overlaid in your field of vision, depending on the model. To do this, they pack components such as microphones, touch controls, motion sensors, and sometimes a camera and tiny projector into the frame and arms of the glasses. Nearby Glasses is an Android hobbyist app that continuously scans for Bluetooth Low Energy “advertising frames”—a type of data—to recognize devices from manufacturers linked to smart glasses, specifically Meta, Luxottica (Meta Ray-Bans), and Snap. When it sees a matching Bluetooth signature, it sends a notification like “Smart Glasses are probably nearby,” though the developer explicitly warns about false positives, for example from Meta Quest VR headsets. Users install it from Google Play or GitHub, enable foreground scanning, start the scan, and then decide how to respond if an alert appears. Because stalkers and harassers misuse smart glasses to target people, the developer built the app in deliberate defiance to modern surveillance after reading reports about people using Meta’s Ray-Ban smart glasses to secretly film others in massage parlors and during immigration raids. In speaking with the outlet 404 Media about the project, developer Yves Jeanrenaud said: “I consider it to be a tiny part of resistance against surveillance tech.” This kind of app matters most in contexts where covert recording or automated identification has real consequences: For people in vulnerable or stigmatized workplaces (e.g., massage parlors, clinics, shelters) where non-consensual filming can lead to harassment, doxxing, or professional harm. During law-enforcement or immigration actions, protests, or political gatherings, where smart glasses could be used for evidentiary recording, intimidation, or bulk identification. In any setting where bystanders reasonably expect not to be recorded or profiled, either because of a sense of privacy or because of the law (public transport, bathrooms, gyms, support groups). In these scenarios it makes sense to want an extra signal that someone nearby may be using surveillance-capable wearables. As observed by the reporters at 404 Media, this app is an imperfect, tech-based mitigation to a social and legal problem: it can misfire, it can’t tell you who is being recorded, and it risks giving a false sense of safety. The developer frames it not as a solution but as a small, user-controlled countermeasure in an environment where surveillance devices are becoming more invisible and more AI-augmented. Browse like no one’s watching. Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
malwarebytes.comFeb 25, 2026extracted
Smart glasses are back, privacy issues included
Smart glasses are back, privacy issues included AI smart glasses are the latest addition to fashion, and they include a camera, a microphone, AI, and privacy risks. After Google Glass failed to gain traction more than a decade ago, the category is seeing renewed interest as companies redesign the technology to look like ordinary eyewear. Meta and privacy The most popular model on the market comes from a partnership between Ray-Ban and Meta, combining mainstream fashion with a company known for privacy controversies. Meta’s position in the market draws attention because of its history with privacy and data practices, raising questions about how information captured by these devices is collected, stored, and used. Two Harvard University students demonstrated that footage from Meta’s Ray-Ban smart glasses could be connected to external facial recognition systems to identify strangers in public. Meta chose not to include facial recognition in the first generation of Ray-Ban Meta glasses, citing ethical concerns. Recent reports suggest the company may revisit that decision for future models. Another issue is what happens after a recording is made. In April 2025, the smart glasses privacy policy was updated. According to the company, photos and videos captured by the glasses are stored on the user’s phone. They fall under AI or cloud policies only when shared to those services. Voice recordings triggered by the wake word are stored in the cloud by default and can be kept for up to a year to help improve AI systems, with no option to opt out beyond manual deletion. What features will be introduced in the future remains to be seen. Encouraged by Meta’s success, other major players have entered the race. Apple and Samsung could be developing similar products. Recording in public spaces is a slippery area The Washington Post reports that devices like Meta Ray-Bans are drawing pushback from Generation Z, who see them as a threat to personal privacy. The issue is not the technology itself, it is how it is used. Content creators are using this technology to film strangers for social media, often without their knowledge or consent. Recording in public spaces is generally legal because people usually have a lower expectation of privacy. Legal experts say the deciding factor is the location where the recording takes place. A number of women have shared experiences about being secretly filmed by people wearing smart glasses in public. One woman said she was approached on a walk, had a conversation with a man wearing glasses that looked like ordinary sunglasses, and only later discovered a video of her was posted online with nearly a million views. Similar incidents have also been reported. In October 2025, the University of San Francisco issued a warning after reports that a man wearing Ray-Ban Meta smart glasses was approaching women on and around campus and recording interactions that may have been shared on social media. Meta Ray-Ban smart glasses include an LED that signals recording, though reports suggest some wearers can pay third parties to disable it. Researchers are working on ways to give bystanders more control and visibility when camera-enabled devices are in use. Smart glasses enter the workplace Use in workplaces and organizations raises additional questions, since these spaces fall outside public settings. A woman visiting a beauty a beauty salon in Manhattan said she was unpleasantly surprised to see her aesthetician wearing Meta Ray-Bans. The worker told her the batteries were not charged, but the encounter still left her uneasy. The company later said employees keep the glasses turned off during appointments. The incident sparked a broader debate about privacy and when it is acceptable to record other people. AI glasses can capture and process sensitive information such as facial features, voiceprints, eye tracking, and other identifiers. In a lot of cases, this data falls under biometric personal data in laws like the GDPR, Illinois’ Biometric Information Privacy Act (BIPA) or the California Consumer Privacy Act (CCPA). For employers and organizations, this matters because biometric data comes with stricter expectations around notice, consent, retention, and use. Missing those obligations can lead to serious legal exposure. Organizations may need written policies on when, where, and how AI glasses can be used. Privacy risks should be assessed based on industry, location, and use case before deployment.
helpnetsecurity.comFeb 5, 2026extracted
Pwn2Own Offers $1m for Zero-Click WhatsApp Exploit
Security researchers attending the upcoming Pwn2Own competition in Cork have the chance to win $1m if they can find a high-impact exploit in WhatsApp. The competition organizers, Trend Micro’s Zero Day Initiative (ZDI), explained late last week that only zero-click vulnerabilities that lead to code execution would be considered for the six-figure cash prize, although smaller awards will be available for other WhatsApp exploits. “We introduced this category last year, but no one attempted it. Perhaps a number with two commas will provide the needed motivation,” said ZDI head of threat awareness, Dustin Childs. The upcoming event, which will take place in Trend Micro’s Cork office from October 21 to 24, is the second time the competition will be held in Ireland. It is focused on consumer products, with eight categories selected: Mobile phones Messaging The SOHO Smashup Smart home devices Printers NAS devices Surveillance system devices Wearables Meta is the main sponsor of the event this year, with Synology and QNAP also putting money into the competition, as well as helping to set up and configure devices for contestants to probe for bugs. As always, the idea is to incentivize some of the world’s most talented security researchers to find exploits in a range of products. This information will then be responsibly disclosed for the relevant vendors to fix, while enabling Trend Micro to protect customers with virtual patches until a full update is available. “We’ve tweaked the mobile category a bit by adding a new USB attack vector for the phones. Hopefully, we’ll see some interesting research come in demonstrating what could happen if a threat actor has physical access to your device,” said Childs. “Last year, we awarded $1,066,625 for over 70 unique zero-day vulnerabilities at the contest. We can’t wait to see if 2025 tops that number – especially with a million-dollar bounty on the table.” Mobile handsets will sit at the “heart of this event,” with contestants able to hack a Samsung Galaxy S25, Google Pixel 9 and an Apple iPhone 16. Other products in the competition will include QNAP, Ubiquiti and Nest SOHO devices, Amazon, Philips and Sonos smart home devices, Meta Quest headsets and Ray-Ban Smart Glasses. Zero-click WhatsApp exploits are often discovered and monetized by commercial spyware companies like NSO Group, which used it to deliver its notorious Pegasus malware. Image credit: Diego Thomazini / Shutterstock.com
infosecurity-magazine.comAug 4, 2025extracted
Lazarus Group rises again, this time with malware-laden fake FOSS
INFOSEC IN BRIEF North Korea’s Lazarus Group has changed tactics and is now creating malware-laden open source software. Software supply chain management vendor Sonatype last week published research in which it claimed that Lazarus Group has created hundreds of “shadow downloads” that appear to be popular open source software development tools but are full of malware. The company says it found 234 unique malware packages built by Lazarus in the first half of 2025 alone. “Lazarus has increasingly pivoted from disruption to long-term infiltration, using tailored malware, modular payloads, and infrastructure evasion techniques to achieve persistent access to high-value targets — including the open source software ecosystem,” the company’s researchers wrote. Lazarus Group’s rap sheet includes the 2014 Sony Pictures hack, the 2016 attack on banks in Bangladesh, and 2017’s WannaCry ransomware attack. Like many other North Korean operatives, Lazarus Group shifted to cryptocurrency theft. Developers who don’t carefully check downloads appear to be the gang’s latest targets. - Simon Sharwood MFA mess costs Canucks big bucks Slow rollout of two-factor authentication has cost the Canadian city of Hamilton CAD$5 million ($3.6 m). In February 2024 the city was crippled for weeks by a ransomware attack that saw criminals demand CAD$18.5 million ($13.4m) in exchange for the decryption keys. The city told them no and then spent CAD$18.4 million ($13.3m) fixing the problem by building a more secure network. At a town meeting last Wednesday, officials said the city's insurance company declined to pay out CAD$5 million ($3.6 million) in costs, saying that the city had broken the contract by not installing multi-factor authentication across its entire network. In 2022 the insurers required the city to install MFA and Hamilton commenced a pilot program the following year Before the city completed its rollout, the ransomware scum attacked. "This has been a test of our system and a test of our leadership," said Mayor Andrea Horwath last Wednesday. "We are not sweeping this under the rug. We are owning it, we're fixing it and we're learning from it." Cyrus Tehrani, acting chief information officer for the city, disputes the claims that a lack of MFA was to blame for the ransomware attack, as the city faced a "highly sophisticated attack on an external, internet-facing server, gaining unauthorized access to the City of Hamilton systems." And there are a couple of upsides to the saga. Firstly the criminals lost out on their big payday, and secondly the city's infrastructure is much more up-to-date, the Mayor said. "This city needed to change," she opined. "This city needed to become more modernized. When I got here I felt this was a city time forgot." We'll see how the voters agree. Bug bounties all round! Fancy becoming an instant millionaire (before tax)? All you'll need is to find a zero-click flaw in WhatsApp that allows code execution, fly to Dublin on October 21, and demonstrate it at the latest Pwn2Own competition. WhatsApp is a focus of this year’s competition, which will pay $500,000 for a single click crack of Meta’s messaging tool. Other big money prizes on offer include winning $300,000 to remotely crack an iPhone 16 or a Pixel 9 handset, $150,000 for no-interaction remote code execution on Meta's Quest 3 and Ray-Ban headsets, and a host of smaller prizes, with a particular focus this year on smart home devices and printers. As ever, if you hack a device you also get to keep it. Last year over 70 zero-day flaws were demonstrated and contestants walked away with combined winnings of $1,066,625 in total. Not to be outdone, this week Microsoft announced increases in the bounties it offers for .NET vulnerabilities. Find something wrong with .NET and ASP.NET Core (including Blazor and Aspire) and you can now win rewards of up to $40,000 for the most serious flaws, up from $30,000 last year. Redmond was a relative latecomer to the bug bounty crowd, starting its first program in 2013 at the prompting of security maven Katie Moussouris. Microsoft used to be considered one of the worst companies for this sort of thing - making legal threats to researchers and refusing to compensate them for their discoveries. But it began to see the benefits and in 2008 publicly vowed not to resort to legal threats. Teams touched up While we’re talking Microsoft, last week it announced that Teams admins will have a slightly easier time of it thanks to some new code. Teams already has an audit logging system that allows admins to quickly check for suspicious activity such as users who have inappropriate control rights or are sharing material that’s not appropriate given their access privileges. An improved logging system Microsoft introduced last week added better timestamp monitoring, plus the ability to log screensharing sessions and all who participate in them. This will be handy for preventing the loss of corporate information, either to competitors, corporate espionage, and - of course - leaky juicy titbits to journalists (hint, hint). CISA swings hammer of Thorium The Cybersecurity and Infrastructure Security Agency (CISA) last week released Thorium, a digital forensics tool developed in partnership with Sandia National Laboratories. The tool allows massive scaling up of file analysis and incident response times and can take in and analyze more than 10 million files per hour. "Thorium enables teams that frequently analyze files to achieve scalable automation and results indexing within a unified platform," the agency said. "Analysts can integrate command-line tools as Docker images, filter results using tags and full-text search, and manage access with strict group-based permissions." Thorium runs at scale on Kubernetes and ScyllaDB systems and has a strict permissions database that controls who can see its output. CISA says it'll be particularly useful for running custom commands for inspecting Docker images, as well as commercial, open source, and proprietary code. Republicans and Democrats agree on banning stingray scanners The use of stingray cellphone monitoring towers by US law enforcement could be curtailed if bipartisan legislation introduced in the House and Senate passes. Stingrays are fake cellphone towers that records the IMEI number and location of any handset in the area. They have been used for nearly a decade but the tech has sparked concerns that the devices are used to conduct mass surveillance. There have also been multiple reports that unknown entities are using such kit for espionage purposes. The Cell Site Simulator Warrant Act, introduced by Senators Ron Wyden (D-OR) and Steve Daines (R-MT), and Representatives Ted Lieu (D-CA), and Tom McClintock, (R-CA) last Thursday, would require police to get a warrant based on probable cause before using the devices, other than in some emergencies. If the bill passes, an Inspector General would audit all stingray use, and any judge ruling on a case using stingray data should be informed on its potential flaws. Police would also be limited to only collecting directly relevant data. "Law enforcement agencies need clear and transparent rules about when it’s acceptable to use stingray phone surveillance, so they can properly investigate crimes without endangering Americans' privacy or violating their constitutional rights," Wyden said. "Our bipartisan bill protects Americans against warrantless stingray surveillance while setting clear rules for law enforcement about when and how they can use these devices." The proposed law will also include a $250,000 fine for anyone illegally stingray devices to spy. Building your own stingray is relatively simple, all it takes is about $1,000-worth of kit and the right software. The bill includes exceptions for those using homebrewed kit for teaching or legitimate research. ®
go.theregister.comAug 4, 2025extracted
Pwn2Own hacking contest pays $1 million for WhatsApp exploit
The Zero Day Initiative is offering a $1 million reward to security researchers who will demonstrate a zero-click WhatsApp exploit at its upcoming Pwn2Own Ireland 2025 hacking contest. The record bounty targets zero-click security flaws that allow code execution without user interaction on the messaging platform used by more than three billion people worldwide. Meta, alongside Synology and QNAP, is co-sponsoring the Pwn2Own Ireland 2025 competition, which will take place from October 21 to October 24 in Cork, Ireland. "As you might have guessed from the title, we're excited to announce that Meta is co-sponsoring this year's event, and they are hoping to see some great WhatsApp exploits. They are so excited for it, we're putting up $1,000,000 for a 0-click WhatsApp bug that leads to code execution," the Zero Day Initiative announced Thursday. "We also will have lesser cash awards for other WhatsApp exploits, so be sure to check out the Messaging section for full details. We introduced this category last year, but no one attempted it. Perhaps a number with two commas will provide the needed motivation." The contest features eight categories targeting mobile phones, messaging apps, home networking equipment, smart home devices, printers, network storage systems, surveillance equipment, and wearable technology, including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets, as well as Samsung Galaxy S25, Google Pixel 9, and Apple iPhone 16 flagship smartphones. The ZDI has also expanded the attack vectors for the mobile category to include USB port exploitation for mobile devices, requiring contestants to compromise locked phones through physical connections. Traditional wireless protocols, such as Wi-Fi, Bluetooth, and near-field communication, remain valid attack methods. Registration closes on October 16 at 5 p.m. Irish Standard Time, with the contest order determined by a random drawing. The Zero Day Initiative operates the event to identify vulnerabilities before malicious actors can exploit them, coordinating responsible disclosure with affected vendors. After the flaws are exploited during Pwn2Own events, vendors have 90 days to release security updates before Trend Micro's Zero Day Initiative publicly discloses them. Last year's Pwn2Own Ireland event awarded $1,078,750 for over 70 unique zero-day vulnerabilities, with Viettel Cyber Security collecting $205,000 for flaws demonstrated in QNAP NAS, Sonos speakers, and Lexmark printers. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 1, 2025extracted