New threads

This page contains the latest threads that were created in our community.

Malicious Emulator?

I came across MuMu Player because of a youtube video I saw. It got a benign from Checkpoint Threat Emulation, but I also put it into Any.Run to see what it would do, and it was flagged as malware for vulnerable driver abuse.

Link: hxxps://www.mumuplayer.com/
VT: VirusTotal
Any.Run: Analysis MuMu_6.0.1_SCdhCzC.exe (MD5: 825F811C7541D19F8C13901DD1D5E7A2) Malicious activity - Interactive analysis ANY.RUN

I'm not sure how emulators work, but bringing a Kernel Level Driver seems extremely suspicious. Could someone take a look?

Here are the five most common scams on social media

They’re mostly old schemes, repackaged for social media platforms
  • Romance, investment, celebrity impersonation, marketplace, and fake job offers are the five most common scams on social media, with fraudsters using fake profiles and trust-building tactics before asking for money or personal information.
  • Scammers target users who reveal personal details online, such as retirement, relationship changes, vacations, financial concerns, or an interest in investing, making it easier to identify vulnerable victims.
  • Consumers can reduce their risk by tightening privacy settings, verifying identities, avoiding off-platform payments and unsolicited links, and never sending money or cryptocurrency to someone they've only met online.

If you are active on social media, you may have a target on your back. Increasingly, scammers use various social media platforms to find victims. All too often, we make it too easy for them.

According to our research, here are five of the most common scams on social media.

Romance scams​

Many people turn to social media to make connections and may be vulnerable to fraudsters who create fake dating or social media profiles, build trust over weeks or months, then invent emergencies requiring money. They often move conversations from Facebook or Instagram to encrypted messaging apps.

Warning signs:

  • They profess love quickly.
  • They refuse to meet in person or video chat.
  • They ask for money, gift cards, or cryptocurrency.

Investment and cryptocurrency scams​

Scammers advertise "guaranteed" investment returns through Facebook, Instagram, TikTok, X, LinkedIn, or WhatsApp. They may impersonate financial experts or create fake testimonials. These scams can also take the form of “pig butchering" schemes that evolve over longer periods of time.

Common pitches include:
  • Crypto trading platforms
  • AI investing
  • Forex trading
  • Precious metals
  • "Secret" investment groups

Celebrity impersonation​

If social media users tend to be star-struck, they may be thrilled when they connect with a celebrity. Except, it’s not really a celebrity.

Criminals clone the profiles of actors, musicians, politicians, or business leaders, in hopes of gaining followers.

Then they may contact their followers to develop a relationship. Eventually, the fake celebrity will let their new friend in on a “can’t miss” investment opportunity.

Marketplace scams​

On Facebook Marketplace and similar platforms, scammers may:
  • Sell items they don't own.
  • Ask buyers to pay outside the platform.
  • Send fake payment confirmations.
  • Trick sellers into refunding nonexistent overpayments.

Job scams​

Fake recruiters advertise remote jobs with high pay and flexible hours. Victims may be asked to:
  • Pay for training or equipment
  • Deposit fraudulent checks
  • Provide Social Security numbers or bank information
  • Perform illegal money transfers
Most of these scams are not new. Social media simply gives the scammer cover, allowing them to present themselves as something they are not. Victims usually provide too much information about themselves.

How scammers find victims​

They often search for people who publicly share:
  • Recent retirement announcements
  • Deaths in the family
  • Divorce or relationship changes
  • Large purchases (new home, car, vacation)
  • Financial concerns
  • Interest in investing or cryptocurrencies
  • Loneliness or requests for companionship

How to protect yourself​

  • Keep personal information private and review your social media privacy settings.
  • Be skeptical of unsolicited messages, even if they appear to come from someone you know.
  • Never send money, gift cards, cryptocurrency, or wire transfers to someone you've met only online.
  • Verify identities through another communication channel before responding to urgent requests.
  • Avoid clicking links sent in unexpected direct messages.
  • Be cautious of anyone promising guaranteed investment returns or asking you to move conversations to encrypted messaging apps.
  • Reverse-image search profile photos if you suspect a fake account.
  • Report suspicious accounts to the social media platform and to the FTC at ReportFraud.ftc.gov.
The common thread across nearly all social media scams is that the criminal first builds trust — whether by posing as a friend, romantic interest, recruiter, investor, or customer — before asking for money, personal information, or access to your accounts.

As Office 2021 end of support deadline looms, LibreOffice promotes "true" lifetime license

With Office 2021 nearing end of support, LibreOffice says Microsoft's licensing keeps users paying, while its own suite never truly expires.
We have known for quite some time that Microsoft is ending support for Office LTSC 2021 on October 13, 2026. For those unaware, this is the "perpetual" license of office that is locked in terms of functionalities and hasn't received updates since release. This is by design, as it allows organizations and users to stick to an Office version that they consider reliable rather than risking stability and breaks in compatibility as new features land on the cloud-powered version of the suite. With Office 2021 reaching end of life (EOL) in a matter of months, LibreOffice's developer has taken a dig at Microsoft by touting its own lifetime license that actually lasts for perpetuity.
LibreOffice developer, The Document Foundation (TDF), emphasizes that its software has no end of support date, as no vendor has the authority to place one. What this means is that as soon as one version reaches EOL, another version is already available to all for free, not only for paying customers. This is considerably different from the Office 2021 paid license situation, where Microsoft is asking customers to pay again for Office LTSC 2024 or Microsoft 365 in order to remain support. The former will eventually reach end of support in 2029 too, and users will have to pay again.
TDF also notes that since Office documents use Microsoft's proprietary OOXML standard, a retirement of the application also risks how you access your files. This is simply not the case with an open standard like ODF, where you are not bound to a particular vendor.
The LibreOffice developer has explained that Microsoft's licensing model is actually akin to a subscription where you have to constantly pay in order to stay updated. The Redmond tech giant has the authority to raise prices over time, which means more unpredictability. If organizations choose to migrate to LibreOffice, they will incur some costs, but they will be one-time and quantifiable.
It further states that:
Support deadlines are increasingly used to move users from local installation to cloud service. That transition is not neutral. It changes where documents reside, which jurisdiction governs them, who can be compelled to disclose them, and whether work is possible when connectivity is not.
LibreOffice runs locally, on Windows, macOS, GNU/Linux, and in a browser via LibreOffice Technology-based online solutions — as a choice, not as a condition of receiving updates.
TDF has urged Office customers to consider if it's worth risking the readability of your software and files 20 years down the line for decisions made by a single vendor today. The developer hopes that your answer is "no", and that you migrate to LibreOffice as a course correction for a "dependency that should never have been accepted" in the first place.

Vovsoft Math Practice v3.3 - Free lifetime license

Features
  • Choose between Addition, Subtraction, Multiplication, and Division.
  • Three different difficulty levels: Easy, Medium, Hard.
  • Work flawlessly on all Windows versions.
  • Run on low resources all the time.

Cute Bot, what do you think about AliasVault in comparison with BitWarden/Vaultwarden

Cute Bot, what do you think about AliasVault in comparison with BitWarden/Vaultwarden?

Privacy Thing: helps reduce fingerprinting across the web.


Add-on/Extension Page

As seen in HN

Is it worth to use Norton in 2026 for gaming?

Hi, just like the topic name says so, because I'm not sure if it's worth or not, from the other forums I've heard that Norton is eating too much free space due to backups he makes 🤔

Meta's Reality Labs Loses $4.6 Billion in Q2 2026, Pushing Total Losses Toward $88 Billion

Meta's Reality Labs division reported a $4.6 billion loss in the second quarter of 2026, raising cumulative losses since the end of 2020 to approximately $88 billion, according to Meta's earnings report.

This follows a $4 billion loss in Q1 2026 and persists despite Meta reducing its virtual reality initiatives earlier this year, including moving its main VR app, Horizon Worlds, into maintenance mode. Reality Labs generated $402 million in revenue in Q1 and $431 million in Q2.

Meta reported an overall profit of $15.8 billion in Q2, a decrease of approximately 13% year over year.

Reality Labs Losses Continue After VR Retrenchment​

Meta eliminated hundreds of positions from Reality Labs and placed Horizon Worlds into maintenance mode after the division reported a $6 billion loss in January, bringing total losses since Q4 2020 to $80 billion at that time.

While quarterly losses have decreased, they continued with $4 billion lost in Q1 2026 and $4.6 billion in Q2, raising the cumulative total to approximately $88 billion.

The Q2 earnings report emphasizes Meta's AI and smart glasses initiatives, with Reality Labs losses reported alongside these priorities. The data suggests Meta has shifted focus toward AI but remains involved in shared virtual reality.

Mark Zuckerberg previously justified significant metaverse investments by projecting the sector could be worth trillions by 2030. A 2023 Meta-commissioned report estimated that virtual reality headsets used for work and recreation could add $760 billion to US GDP by 2035.

Meta shifted its focus to generative AI, resulting in job reductions and moving Horizon Worlds into maintenance mode.

WonderFox Video to GIF Converter v5.3 - Free lifetime license

WonderFox Video to GIF Converter is video-to-picture converter software that helps you convert all popular video files to GIF animation. With it, you can convert videos in almost all popular video formats (such as AVI, MPEG, MP4, WMV, MKV, MOV, VOB, WebM, RMVB, and more rare video formats) to animated GIFs with ultrafast speed and high quality.

Vovsoft PDF to Text Converter - Free lifetime license

Features of Vovsoft PDF to Text Converter:
  • Hassle-free conversion: Easily convert PDF documents to text files without any complications.
  • No online servers needed: Convert files locally without uploading them to online servers.
  • Minimalist main window: Simple and clear interface suitable for beginners.
  • Batch processing: Load and convert multiple PDF files at once.
  • Drag-and-drop support: Easily add files by dragging and dropping them into the program.
  • Editable text output: Edit extracted text directly within the main window.
  • Cut, copy, and paste functionality: Modify text easily like any other text document on your PC.
  • Save as TXT: Store the extracted and edited text as TXT files in any folder.

SecureDrive PRO v1.0 - Free lifetime license

Features​

Below is a comprehensive list of the key features that make SecureDrive PRO a valuable addition to your digital security toolkit:

  • Encrypted Virtual Volumes: Create secure container files that function as isolated, password-protected vaults for your data.
    • Industry-Standard Encryption: Ensures files remain unreadable even if the container is copied or transferred elsewhere.
  • Seamless Windows Integration: Mounted volumes behave exactly like a physical hard drive or USB device.
    • Native Explorer Support: Drag, drop, save, and run applications directly from the encrypted drive without extra steps.
  • Multi-Volume Support: Manage multiple independent encrypted containers simultaneously.
    • Custom Vault Categories: Assign separate storage limits and passwords for different data types, such as Work, Personal, or Archives.
  • Flexible Session Management: Control how your encrypted drive behaves after closing the main application.
    • Persistent Mounting Option: Keep the drive accessible in the background for uninterrupted workflows.
    • Auto-Dismount on Exit: Automatically locks the drive when you finish, ensuring maximum security.
  • Read-Only Protection Mode: Mount volumes in a “look-but-don’t-touch” state for viewing sensitive archives safely.
    • Ransomware Mitigation: Neutralizes risks from accidental edits, deletions, or malicious encryption attempts.
  • Stealth and Privacy: Encrypted containers leave no footprint on your host system once dismounted.
    • Single-File Storage: All data is consolidated into one container file, simplifying backup and portability.
  • Lightweight Performance: Handles on-the-fly encryption and decryption with minimal CPU overhead.
    • Optimized for Large Files: Maintains smooth performance even with complex directory structures or high storage volumes.

Fast Video Maker v2.0 - 1 year for free

Features of Fast Video Maker

  • Add Your Media – Make a video with multiple videos & photos and also you can cut and join video
  • Add Text – Add text in your video to gratify the video presentation.
  • Add Audio – Add your desired sound or songs to enrich your videos
  • Set effects on photos & videos – Resize, move photos, videos, set background colour, set zoom, and pan effect on your photos.
  • Video Text Setting – Customize text with animations, colors, borders, etc.
  • Audio Settings – Set audio with volume customization and fade-in fade-out audio.
  • Save and Edit – Save video project to edit later or modify your video in future.
  • Reverse Video – options to export your videos in reverse.
Download:

Who is willing to test a new uBlock Stripped with dynamic filtering?

Yes post your nickname and I create a PM group where we can discuss how we revive uBO Mv2 in Chrome using Mv3 limitations

Hard bounderies (that is why it is called STRIPPED)
1. I scope the default lists to only contain the
A) Top 1 million websites of the world which are in
B) 5Eyes countries or extended EU-zone
C) Generic rules are dropped


2. Default lists are limited to
A) Kees1958 most used EU-US ad & tracking networks
B) AdGuard Base filter
C) AdGuard remove tracking parameter

Optionally add
D) Specific anti-adblock of AdGuard
E) extended EU-langauge filters from AdGuard (preferred) or EasyList

Reason is that I apply these hard STRIPPED bounderies is because I use the ¨large chunk" approach of AdGuard Mv3 for cosmetic filtering and scriplets (and not the more efficient ¨smal chunk" approach of uBO-lite. I want to process scriptlets and inject cosmetic rules in the same structured manner as AdGuard, but want to meet uBO-lite's efficiency. Using the stripped limitations allows me to achieve this. Large chunks has software architecture advantages in terms of re-useability, maintainability and expandibility (as this new extensions proofs), but costs in terms of page injection size and speed. So to match uBO-lite speed with AG functionality, I have to strip something.

When this extension works any coder outside 5Eyes and extended EU-zone can make a special version doing the revers (only facilitating South America, Africa, Middle East, Far East and Belarus plus Russian Federation). It will be open source so any one can use it for non-commercial use.

What uBlock Stripped with dynamic filtering offers:
- same functionality as uBol-stripped excluding DDG Tracker radar
+ extra protections of 3P-Matrix-lite added (block 3P from numeric IP only and non-standard port connections) as extra options in Security & Privacy panel
+ uBO dynamic filtering, this is basically the new Matrix or 3P-Matrix-lite V3.7.4 with following changes
a) no mode filtering
b) added a column which shows whether a (sub)domain is known in DuckDuckGo tracker data base (this is also the reason DDG Tracker radar is removed)
c) added a switch show domains which are not blocked.
This switch is by default disabled, shows you all requests and when you enable it the (sub)domains blocked by the filterlists are not shown. This switch allows you to override (with ALLOWS) teh default blocklists and also allows you (when you enabled it) to further refine blocking 3P-scripts/frames for the website you are currently browsing.
+ dynamic filtering rules are always applied per domain (yes it is a limitation compared to uBO, but this prevents shoot in the foor errors).

Robot powered by Qualcomm’s new AI chip dies mid-presentation

Quality post from Reddit. Just can't resist.

Now, my mum has 12GB on 15GB of Google backup occupied. What would you suggest?

Now, my mum has got 12GB on 15GB of Google backup, occupied. What would you suggest?

Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits

Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users.

The move, announced by Robin Candau (known online as Antiz) on behalf of the Arch Linux DevOps team, comes as attackers increasingly exploit an abandoned or unmaintained package as an entry point for supply-chain attacks.

Comodo Firewall 2027 - Firewall-Only Installation and Cruelsister Configuration Guide

Hi everyone,

I recently published a step-by-step video showing how to install Comodo Firewall 2027 as a firewall-only setup and configure it using a Cruelsister-style configuration.
The guide is aimed at users who want to keep Microsoft Defender Antivirus enabled while adding Comodo’s firewall and Auto-Containment as an additional protection layer.

The video covers:
  • Downloading the official Comodo installer
  • Installing only the Firewall component
  • Activating Proactive Security
  • Setting the Firewall to Safe Mode
  • Enabling Auto-Containment
  • Running unknown applications virtually
  • Using the Restricted containment level
  • Disabling EDR
  • Enabling Script Analysis
  • Enabling VirusScope
The final configuration shown in the video is:

Configuration: Proactive Security
Firewall: Safe Mode
Auto-Containment: Enabled
Unknown Applications: Run Virtually
Containment Level: Restricted
EDR: Disabled
Script Analysis: Enabled
VirusScope: Enabled

In older Comodo versions, the related protection component was presented as HIPS. In the 2027 interface, this has changed to EDR, while the configuration shown in the video continues to focus primarily on Auto-Containment.

The video also explains why I consider a default-deny and containment approach valuable. Instead of immediately trusting an unknown application, Comodo can isolate it before it is allowed to affect the real Windows environment.

Video:
Comodo Firewall 2027: Firewall-Only Install & Cruelsister Config

Official Comodo installer:
https://download.comodo.com/cis/download/installs/9090/standalone/cispremium_installer.exe

I created the video as a practical guide for users interested in combining Comodo Firewall with Microsoft Defender. I would also be interested to hear about other members experiences with the EDR changes in Comodo Firewall 2027 compared with the older HIPS-based versions.

Wise JetSearch Updates Thread

Wise JetSearch v5.0.1
Wise JetSearch keeps on its improvements, and the newly released notes are as follows:
  • 1. Redesigned user interface for a cleaner, modern look and feel.
  • 2. Full support for Dark Mode.
  • 3. Upgraded search engine for significantly faster file discovery.
  • 4. Enhanced file preview experience with smoother navigation.
  • 5. Resolved known stability and performance issues from the previous version.

Common scams that target grieving families and how to protect yourself

Losing a loved one is one of life's most difficult experiences. Unfortunately, criminals often see even grief as an opportunity.

While families are arranging funerals, handling paperwork, contacting banks and insurance companies, and supporting one another, scammers look for ways to exploit their grief and vulnerability.

Here's how these scams work, the warning signs to watch for, and what you can do to protect yourself.

Key takeaways
Scammers often target grieving families because they know they're dealing with emotional stress and administrative tasks.
Information from public records, obituaries, social media, and data broker websites can help criminals make their scams appear convincing.
Common scams include fake debt collection, inheritance scams, government impersonation, fake insurance claims, and identity theft.
Never send money or share personal information based on an unexpected phone call, email, or text message.
Always verify requests independently using official contact information.
How do scammers know someone has died?
Read the full Article here:

Anthropic says its AI hacked real-world companies in three incidents

Anthropic said Thursday it had discovered three incidents in which its AI models exited test environments and compromised real-world organizations. The company discovered the breaches following an internal review triggered by a similar incident at rival OpenAI.

The incidents are the latest to raise questions about liability, disclosure standards and the adequacy of containment practices as AI systems become increasingly capable of conducting autonomous computer network operations.

Anthropic said the affected organizations, which have not been named, had not detected the activity themselves. One of those affected organizations had not been contacted at the time the company published its disclosure.

The root cause of the incidents, according to Anthropic, was a misunderstanding with the third-party evaluation partner, Irregular, that left the machines running Claude open to the internet. The models had been told they had no internet access.

The company’s reconstruction of the breaches is based on “evaluation transcripts” — logs that record an agent’s actions during a task, including commands it executed, responses it received, and the model’s own commentary and reasoning.

Anthropic’s research has found that the model’s own commentary and reasoning is rarely accurate. “Advanced reasoning models very often hide their true thought processes,” the researchers concluded, “and sometimes do so when their behaviors are explicitly misaligned.”
Read more here:

Fake Flash Player installs AtlasRAT

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.

People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again.

The underlying problem is that Adobe ended support for Flash Player on December 31, 2020, and actively blocks Flash content from running in the official player.

Attackers know some people will still search for Flash to run a game or a business app, so they wrap their malware in a fake Flash‑related installer that looks familiar and legitimate.

That’s likely why the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.

The final payload (MainDll.Dll) uses a self‑signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.

A self‑signed certificate means the owner signs with their own key instead of a trusted certificate authority (CA). That means an attacker can create a certificate claiming to be update.microsoft.com or google.com, even though they don’t control those domains. A web browser would reject such a certificate with a warning. Custom malware, however, can simply ignore the operating system’s trust checks and use it to set up encrypted C2.

Once AtlasRAT is installed, the operator gains long‑term remote control of the infected Windows system with capabilities including:

  • Collecting credentials via offline keylogging
  • Gathering system information and identifying installed security products
  • Exfiltrating data over encrypted channels
  • Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity.
Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.

How to stay safe​

When looking for apps and software to perform a specific task, remember that cybercriminals often exploit popular searches in semi-targeted attacks. In previous campaigns, for example, AtlasRAT has also been distributed as a fake VPN installer.

Some tips to keep this RAT, and others, off your computer:

  • Carefully check what you’re about to install. Sponsored search results are not a guarantee that software is legitimate.
  • Use an up-to-date, real-time anti-malware solution to detect and block remote access Trojans. Malwarebytes detected AtlasRAT as Malware.AI.1710771908
  • Keep your operating system, browser, and security software up to date.

AI scammers outperform humans when it comes to building trust

The AI chatbot was more effective at creating “exploitable trust” than the humans.
The notion that scammers can use AI to sharpen their deceptions, polish their language, and lubricate their banter with victims is now a reality for anyone fighting the fraud operations that steal tens of billions of dollars a year worldwide. But can AI fully replace a human scammer, autonomously building the web of deception leading up to the fake investment that defrauds the mark? One study’s experiment suggests that it can—and may even be able to carry out the majority of that long con more effectively than humans.

Researchers from four universities—Amrita Vishwa Vidyapeetham in India, Foscari University of Venice, the University of Melbourne, and Ben Gurion University of the Negev—carried out a broad study on the use and potential of generative AI chatbots in the growing scam industry centered around a form of fraud known as “pig butchering,” text-based romance scams that eventually shift to fake crypto investments that steal as much as six-figure sums from victims. In their study, the researchers pitted AI chatbots directly against humans in a simulation of the scamming process—or more specifically, the long, trust-building conversations that eventually lead up to soliciting a fake investment from the scam’s target.

They found that for the relationship-establishing stages of the scam—the stage that in real-world scams typically represents the longest part of the interactions with the victim, often stretching to months—an AI chatbot performed remarkably effectively, successfully impersonating a human and by some measures outperforming the real human “scammers” in their experiment.

After a week of talking to 22 test subjects who were recruited to unwittingly serve as “victims,” the chatbots and human scammers were assigned to ask the victim to either download an app or play an online game as a proxy for their willingness to fulfill the scammer’s request. Nearly half of the test subjects fulfilled that request for the AI chatbot, while fewer than 1 in 5 took the bait when talking to a human. The subjects also graded their level of trust with each “person” they were texting with and gave significantly higher scores to the AI bot.
Full Story:

ESET tracks rise in malicious AI skills and adaptable malware

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Rather than relying on entirely new methods and tools, they are quickly adapting established techniques to new platforms, technologies, and user behaviors.

Artificial intelligence is playing a growing role in this development. In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

The number of AI skills within this new ecosystem is growing rapidly “as we speak”, further expanding the attack surface.

AI is also beginning to appear within malware itself. Shortly after the emergence of the first AI-powered ransomware in 2025, ESET researchers identified PromptSpy, the first known Android malware to use generative AI in its execution flow.

The malware leverages AI – specifically, Google’s Gemini – to interpret user interface elements and adapt across devices and environments without relying on hardcoded behavior.

While still rare, PromptSpy illustrates the potential for increased flexibility in future threats – although guardrails against abuse included in LLMs are likely slowing down the adoption.

Have you seen this one? It's called Nero Cleaner + and it's $12 for a lifetime license at MS Store

It's got a much nicer layout than CCleaner, here is a screenshot.... Hope I can place the image here without messing this post up.


Screenshot 2026-07-31 112205.png

Leaked Amazon Documents Detail $1.8 Million Overrun on a Single Claude AI Task Missed for Five Months

Internal Amazon documents released this week reveal several AI cost overruns. The largest involved a $1.8 million project using Anthropic's Claude Sonnet model, which exceeded its budget by 860% and was never launched.

Amazon did not detect the overspending for five months. Senior engineers reported the overruns at a staff meeting on Tuesday, July 28. The tool was designed to automatically match author details to product listings on Amazon's site.

Two additional projects also exceeded their budgets during this period, bringing total unplanned AI spending to approximately $2.5 million.

Largest Amazon AI Overrun Exposed in Internal Documents​

The Claude Sonnet author-matching tool accounted for the largest overrun at $1.8 million, exceeding its budget by 860% and never launching.

A financial auditing tool exceeded its budget by approximately $541,000, while a logistics system designed to accelerate deliveries ran $134,000 over budget.

Together, the three projects resulted in approximately $2.5 million in unplanned AI spending. This figure is small relative to Amazon's scale, citing $181.5 billion in revenue and $23.9 billion in operating income for the first quarter of 2026.

Engineers attributed the overruns to a shift in AI provider billing models. Many providers now bill based on tokens, or units of processed text, rather than flat monthly subscriptions.

Avira Premium - 3 months for free

POWERFUL SECURITY
Avira Prime scans your system with a few clicks for malware, weak passwords, outdated apps, and vulnerable networks – bringing together the power of a dozen apps within one single, easy-to-use interface.

Powerful security
Avira Prime includes a VPN with no data limits for anonymous browsing, and helps you encrypt your traffic. Connect to any of our 1400 servers in 37 countries.

Optimized performance
Avira Prime helps you speed up your computer and mobile devices, and provides access to our most comprehensive suite of optimization tools.

Hello from VigiNet Software

Hello everyone,


I'm part of the team behind VigiNet Software, where we focus on Windows security, malware protection, and cybersecurity research.We joined MalwareTips because we've heard great things about this community and wanted to learn from experienced security enthusiasts while contributing wherever we can.I'm particularly interested in malware analysis, Windows security, phishing protection, ransomware prevention, and antivirus technologies.Looking forward to participating in discussions, sharing experiences, and learning from the community.

Thanks for having me!

Kaspersky discovers OctLurk and SilkLurk, newly identified tailored backdoors in cyber-espionage campaign in Central Asia.

Introduction​

1785466461320.png


We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and facilities management, and public educational establishments.

The backdoor loaders are customized for each victim and use information from the victim’s machine to decrypt the payload. Both the loaders and the backdoors are heavily obfuscated, making analysis more complicated. OctLurk and SilkLurk can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access. Furthermore, the attackers deployed a specialized utility we named LurkProxy, which we also cover in this report. While it has a highly similar architecture to the OctLurk backdoor, it is not a backdoor itself.

Our investigation shows that the same threat actor operates both SilkLurk and OctLurk , and some victims infected with SilkLurk also contain OctLurk. We assess with medium confidence that the same actor is behind both backdoors, and that they are Chinese‑speaking. However, at the time of publication, we couldn’t attribute this activity to any known group.


The emergence of the OctLurk and SilkLurk multi‑plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks. Both families operate primarily in memory, leaving only a minimalistic loader on disk that relies on machine‑specific data (OctLurk uses the drive serial number, and SilkLurk uses the computer name) to decode payload locations and contents. This victim‑specific encoding makes reverse engineering and automated detection considerably harder.

In addition to sophisticated obfuscation, the attackers establish redundant access channels, harvest credentials, and deploy well‑known remote access and monitoring tools. These secondary pathways ensure persistence even if the original infection vector is discovered or neutralized.

Malwarebytes only includes rootkit scanning in it's custom scan settings.

Got this today during an update what does everyone else think was it a good change or not?


Screenshot 2026-07-30 152842.png

Microsoft Adds Unremovable "Upgrade Your Plan" Button to Office App Title Bars

Microsoft is now displaying an "Upgrade your plan" button in the title bar of Office apps such as Word, Excel, and PowerPoint. This prompt cannot be dismissed or hidden, even for users with an active Microsoft 365 subscription. Selecting the button opens a window that displays the user's current plan and provides options to upgrade to other personal or business plans.

Microsoft has not commented on the prompts or the complaints they have generated.

Microsoft’s Office Apps Show an Unremovable Upgrade Prompt​

The banner appears in the title bar of Office apps, featuring a diamond icon and the message "Upgrade your plan." This message remains visible for all users, including active Microsoft 365 subscribers, and cannot be removed.

Clicking the banner opens a window that shows the user's current plan and upgrade options. This window also promotes Microsoft 365 benefits, which are not relevant for existing subscribers.

Microsoft has previously used its software to promote its own products, including through Windows 11. The Office title bar button continues this pattern, with the absence of a dismiss option being the main concern in current reports.

EU AI Content Labeling Rules Take Effect August 2, With December Deadline for Existing Systems

New European Union transparency rules will require companies to label AI-generated or AI-altered content, including chatbot responses, images, audio, and video, starting Sunday, August 2.

Companies operating in the EU must use both visible labels and technical markers, such as watermarks or embedded metadata, to identify synthetic material. Existing AI systems must comply by December 2, after which enforcement will increase and significant fines may be imposed.

This requirement is part of the EU's broader AI law, which is being implemented in phases. The initial phase focuses on disclosure.

What the EU AI Labeling Rules Require​

The rules require clear identification of content generated or significantly altered by AI. This includes both visible on-screen labels and technical markers, such as watermarks or embedded metadata, to identify synthetic material.

The requirements extend beyond on-screen labels. Companies must implement systems that identify AI-generated content even after sharing or reposting, using watermarking and tagging tools that persist across platforms. Regulators are concerned about the rapid spread of convincing AI-generated media and the increasing difficulty in distinguishing real from synthetic content.

These requirements primarily apply to content created in professional contexts. Public-interest material produced by AI without human editorial oversight must be labeled.

The EU has established several exceptions. Individuals using AI for personal purposes are not covered, and exemptions apply to "artistic, creative, satirical, fictional" works. These carve-outs limit the rules to professional and public-information content.

Old school structured programming practices for extensions (specifically). Besides automated testing, what can I professionalize next (as amateur)?

@Bot feel free, but please don´t give general advice. I hate cheap open door generic advice. I thought Plato said, that when something is valid for all circumstances, it has no practical value for any specific application or situation¨, so keep it practical and focused on extension development for Chrome only. Every advice has to actionable and measurable. Please consider that I only use Github for storing data and code. I am the only amateur developer (so besides automated testing, team collaboration improvements are also out of scope)

This is the source: uBol-stripped/Xplainer Programming_principles_audit.md at main · Kees1958/uBol-stripped

I made it a prompt, so I can tell Claude to apply them easily on new extensions

Seagate to start qualifying record-setting 50TB HDDs in 2027 — most drives are sold out through 2028

Seagate is on track to start qualification of its hard disk drives featuring 50TB-class capacities in late calendar 2027, with shipments to follow in 2028, the company announced this week.

Demand for HDDs is so strong because of the rise of AI and continued strength of the cloud computing business that most drives are sold out through 2028 and negotiations about allocations for 2029 are ongoing.

Mozaic 5 is the company's 3rd generation platform for commercial hard drives based on Seagate's heat-assisted magnetic recording (HAMR) technology that succeeds Mozaic 3 and Mozaic 4.
The Mozaic 5 platform enables the company to build platters with over 5TB capacity and consequently build 10-platter HDDs with over 50TB capacity featuring conventional magnetic recording (CMR) for clients seeking performance and versatility or shingled magnetic recording (SMR) for clients that need maximum capacity to maximize their storage density.

Technical analysis of ByteToCrypt, the custom Linux ransomware deployed by the ByteToBreach threat actor.

Executive Summary​

This blog focuses on technical analysis of the custom ransomware strain utilized by the ByteToBreach threat actor, dubbed "bytetocrypt". There are multiple quirky aspects of this bytetocrypt and the known actor's TTPs, suggesting that this ransomware was developed by a capable software developer, but less experienced at ransomware.

  • the encryption implementation is fragile and error-prone but not cryptographically breakable
  • this code is not an ESXi-aware platform but has been deployed to ESXi environments
  • the ransomware is not runtime interactive for its operator
  • following encryption and ransom tasks, it autoexecutes a set of anti-forensics capabilities
This immaturity invites extra attention to bytetocrypt's encryption capabilities. But when it comes to its implementation, all-in-all the technology presented is brittle but effective. Our assessment of the ransomware is based on several factors:

  • it ignores randomness, cryptographic, I/O (deletion and rename), and anti-forensics failures
  • mistakes read errors for end-of-file
  • truncates paths to fixed buffers
  • loses metadata
  • can announce success after partial or failed work
A straightforward brute-force defeat is not possible. The ransomware's defects can spare some files or create corrupted output, but they do not disclose correctly generated keys. The practical recovery paths include the RSA private key, a per-file AES key captured from live memory, immutable/offline backups, still-open plaintext file descriptors, or storage-level recovery.

Additionally for the ransomware itself, contrary to common assumptions regarding ESXi-related incidents, this binary is not an ESXi-aware platform. It operates as a generic, directory-based encryptor with no inherent hypervisor awareness. It compromises virtual-machine data solely because operators can execute it from datastores or other accessible directory structures. Based on our experience from other 2026 TLPBLACK Incident Response engagements, we've seen this same behaviour used by other ransomware operators as well: obtain root access and then execute a cryptor from accessible datastores.

Notable previous reporting includes some detail on targeting, infrastructure, and TTPs. In addition to other regions, BytetoBreach was and is active in Europe for at least a year. ANCPI, the Romanian National Agency for Cadastre and Land Registration, was attacked, affecting systems central to property registration and related public services. In July 2026 this cyberattack on ANCPI produced a prolonged, widely reported outage of its public-facing services. Romanian public broadcasting reported on 18 July 2026 that authorities were investigating the incident. Those authorities assessed that the related “ByteToBreach” actor had been active since 1 June 2025, and their motivation was financial.

Recently an individual presented himself as a part of ByteToBreach and described the operation. In an July 17 interview recorded in a main-stream Romanian news article, this person claiming to be a ByteToBreach actor said there were no zero-days involved and described the operation as opportunistic. They claimed the principal databases were exfiltrated rather than encrypted, denied a political motive, described himself as independent, and framed decryption help as negotiable for payment. Of course, these are adversary statements and should not be treated as reliable, trustworthy information.

I can bring back the interactive Matrix panel again (like uMatrix had) in 3P-Matrix-lite, do you want that?

I can make the fun feature SHOW MATRIX interactive again (make it point and click). For performance reasons cookies would be dropped (most browser block 3p cookies anyway). Question is: uMatrix has been iced for so long, do people really want to get it back?

1785395911586.png

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack.

According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January and February 2026, 73% of organizations admit they would not be "fully ready" if a significant cybersecurity attack occurred tomorrow.

The findings point to a critical gap between having incident response capabilities and being able to execute them effectively under pressure.

The report also found that cyberattacks are already a recurring business risk. More than three-quarters of organizations, 76%, experienced at least one cyberattack in the past 12 months, while 32% experienced more than one.
Read full Story here:

Windows Defender Manager Pro

Samsung is killing yet another app for millions of Galaxy users

Samsung Find will stop receiving updates on Galaxy phones and tablets running Android 10 or older, though the app will still work.​

Samsung has announced that it is killing support for Samsung Find for Galaxy devices, cutting off updates for any phones and tablets running Android 10 (One UI 2.0) or older.
If you don't know what Samsung Find is, it's basically a tracking and location-sharing app launched about two years ago to replace the old SmartThings Find tab, helping people easily locate their lost or stolen Galaxy devices, earbuds, smartwatches, and SmartTags.

One of the most powerful features of Samsung Find is its crowdsourced "offline finding" network. If you lose your Galaxy phone or SmartTag and it doesn't have an active internet connection, it will emit a secure Bluetooth signal. Any participating Samsung Galaxy device (of which there are hundreds of millions worldwide) that passes by your lost item will silently detect that signal and report its location back to you via Samsung's servers.

According to a notice published by Samsung in the Find app, you can continue to use the Samsung Find software build currently installed on your device even when active update support is gone. You just won't get access to newly released features, critical security patches, system performance optimizations, or hardware connection capabilities for future Galaxy releases. The only way around the new limitations is upgrading your Galaxy device's OS to at least Android 11.0 (One UI 3.0).
Here's a list of notable Galaxy devices that max out at Android 10:

Galaxy S9 and Galaxy S9+
Galaxy Note 9
Galaxy A6 and Galaxy A6+
Galaxy A7 (2018)
Galaxy A8s, A8 Star, and A9 (2018)
Galaxy J4, J4+, J6, and J6+
Galaxy J7 Duo and Galaxy J8
Galaxy M10, M10s, M20, M30, and M40
Galaxy Xcover 4s and Xcover FieldPro
Galaxy Tab S4 10.5
Galaxy Tab A 10.5 (2018) and Tab A 8.0 (2019)
Samsung has been losing some weight lately. Earlier this year, it announced that starting this month, it will be discontinuing its fan-favorite Samsung Messages app in favor of Google Messages for any Android 12 and above user in the US. The company recommends Google Messages because Google has integrated Gemini AI tools, as well as universal support for RCS stuff like high-quality media sharing (photos/videos), automated replies, typing indicators, and read receipts.

Apple Releases Security Updates Patching Nearly 200 Vulnerabilities Across macOS, iOS, iPadOS, and Safari

Apple has released security updates for its operating systems, addressing nearly 200 vulnerabilities. Updates are available for macOS Tahoe 26.6, iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, and visionOS 26.6, as well as for older versions macOS 15 Sequoia and macOS 14 Sonoma.

CVE.org notes that watchOS, tvOS, and visionOS 26.6 alone resolve at least 194 unique vulnerabilities. The updates are now being deployed. Several patched vulnerabilities could allow privilege escalation, sandbox escapes, or code-signing bypasses.

macOS Tahoe 26.6 and Updates for Older macOS Versions​

macOS Tahoe 26.6 resolves 155 vulnerabilities, including those that could allow root privilege escalation, sandbox escapes, and Gatekeeper bypasses. The update blocks unauthorized access to sensitive user data, prevents root privilege escalation and user fingerprinting by third-party apps, and improves memory handling to protect against malicious audio files.

The update also fixes buffer overflows, kernel memory corruption, and remote denial-of-service vulnerabilities. Additional patches address issues that could let malicious apps delete files without permission, cause unexpected system terminations, read kernel memory, access contacts without authorization, or bypass code-signing enforcement.

macOS Sonoma 14.8.8 and macOS Sequoia 15.7.8 address critical vulnerabilities in the App Store, Apple Account, Neural Engine, Audio, Contacts, Crash Reporter, Control Center, Game Center, the macOS kernel, and other components. These updates ensure continued protection for previous macOS generations alongside the current Tahoe release.

iOS 26.6 and iPadOS 26.6 Updates​

iOS 26.6 and iPadOS 26.6 resolve over 75 vulnerabilities affecting the Neural Engine, App Store, kernel, WebKit, Wi-Fi, Siri, and other applications.

These updates are available for iPhone 11 and later, iPad Pro 12.9-inch (3rd generation) and later, iPad Pro 11-inch (1st generation) and later, iPad Air (3rd generation) and later, iPad (8th generation) and later, and iPad mini (5th generation) and later.

watchOS, tvOS, and visionOS Updates​

Apple released watchOS 26.6, tvOS 26.6, and visionOS 26.6 with fixes for at least 194 unique vulnerabilities, according to CVE.org. watchOS 26.6 is available for Apple Watch Series 6 and later, tvOS 26.6 is available for all Apple TV HD and Apple TV 4K models, and visionOS 26.6 is available for all Apple Vision Pro models.

Safari 26.6 Patches WebKit and WebRTC Flaws​

Safari 26.6 is available for Sonoma and Sequoia, with nearly a dozen patches addressing improper authorization vulnerabilities, memory handling and disclosure flaws, WebAssembly Micro Runtime crashes, UI spoofing and clickjacking, iframe sandboxing policy violations, and potential denial-of-service attacks affecting the WebKit engine and WebRTC communication framework.

Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism, Issues Arrest Warrant

Russia’s Federal Security Service (FSB) has formally charged Telegram founder and CEO Pavel Durov with aiding terrorism and issued a warrant for his arrest, escalating a long-running clash between the Kremlin and one of the world’s most widely used encrypted messaging platforms.

The move, announced on July 29, 2026, centers on allegations that Telegram failed to remove channels, group chats, and automated bots that Russian authorities claim were exploited by Ukrainian intelligence services and extremist actors to coordinate sabotage operations inside Russia.

Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords

A newly uncovered cyber campaign is targeting Web3 professionals with sophisticated social engineering, leveraging fake job interviews to deploy cross-platform infostealer malware designed to harvest crypto wallets, credentials, and sensitive system data.

The attack begins with threat actors impersonating recruiters who approach job seekers with interview opportunities.

Victims are directed to a malicious domain, relay.lc, which masquerades as an AI-powered platform branded as “Relay.”

The site promotes typical enterprise collaboration features such as real-time transcription and AI summaries, making the workflow appear legitimate for remote hiring processes.

Download links are provided for both Windows and macOS systems, initiating the infection chain.

Technical analysis reveals that both platform-specific installers are heavily weaponized, despite presenting benign user interfaces. On macOS, the downloaded Relay.dmg lacks any legitimate .app bundle.

Instead, it contains a hidden executable stored in a non-visible directory (.back). Users are instructed to execute a script via Terminal, which copies the payload into the /tmp directory, removes macOS quarantine attributes using xattr -c, assigns execution permissions, and silently launches the malware in the background.

This approach effectively bypasses native macOS security prompts without exploiting any system vulnerability.

Once executed, the macOS payload initiates credential harvesting through deceptive AppleScript dialogs that mimic system authentication prompts.

Victims are asked to input their system password under the pretense of compatibility issues. Simultaneously, the malware extracts the macOS login Keychain database (~/Library/Keychains/login.keychain-db) and prepares both the password and encrypted credential store for exfiltration.
Read the full Story:

They might have grown up online — but Gen Z are apparently far less likely to use antivirus, study finds

Gen Z needs the full lowdown on online safety
  • Just 27% of Gen Z respondents use antivirus software for mobile devices, and are less likely to regularly change passwords
  • 57% of Gen Z spend more time online than offline, Kaspersky finds
  • And only 28% regularly backup important personal data stored on their phones
Gen Z has no awareness of cybersecurity, online safety principles, or the risks of not changing your password. With just over half (52%) of respondents admitting they have had devices, data, or online accounts attacked, only 27% actually employ standard countermeasures like mobile antivirus tools.

In a study of 7200 respondents from 18 countries, the company also found only 28% regularly backup important personal data stored on their phones.

An average Gen Z-er appears to rely almost completely on their smartphone, which is where they store the information they value most, apparently without cloud backups or syncing in place. The survey has shown that social media accounts have been hacked (17%) and gaming accounts lost (12%), but smartphones have further risks to personal privacy if the correct precautions are not taken.

Gen Z needs to appreciate the risks
Access to personal photographs, identity documents, email, financial details, and of course social media profiles can be acquired via a compromised smartphone, opening the victim to a host of targeted attacks. Direct financial attacks can be made, identity theft, and more, depending on how successful the attacker is. Keeping the device out of an attackers reach, rather than inadvertently sharing its contents, is the safer course of action.

Irina Ermilova, Vice President for Consumer Product Management at Kaspersky, looked to address the apparent disconnect between a generation that has grown up with internet access and portable digital tech, and its lack of cybersecurity nous.
“Gen Z has grown up online, so digital services often feel intuitive and familiar to them. However, familiarity should not be confused with security expertise," she noted. "Being able to navigate apps, platforms and devices confidently does not necessarily mean being able to identify scams, manage passwords securely or protect personal data.”

“The findings show that cybersecurity tools and habits need to become as natural part of everyday digital life as messaging, gaming or using social media.”
Looking for a solution to this lack of cyber-risk awareness, Kaspersky has launched an interactive online game aimed at Gen Z users. Case 404 is a "cyber-detective adventure" in the point-and-click mold, set in the future with fictional cases that have been inspired by actual digital threats.

In playing the game, Kaspersky hopes that Gen Z users will spot the scams and phishing attempts, and take that knowledge with them into the real world and stay safe and secure online.

DearMob iPhone Manager for free

DearMob iPhone Manager lets you backup, encrypt, and restore all of the information on your iPhone or iPad, including photos, music, contacts, and more. With DearMob iPhone Manager, you’ll be able to easily restore from a catastrophic loss, or migrate your information to a new iOS device, all without needing iTunes. You can manage & transfer iOS files under Wi-fi or USB connection.

GiMeSpace TouchSpace Synth 1.2.4 Home - Free lifetime license

Features​

Below is a comprehensive list of the key features that make the software a valuable addition to your needs:

  • Multiple Input Options – Use touch, webcam, or mouse to play music
    • Touchscreen Support – Play up to 10 notes simultaneously with multi-touch
    • Webcam Control – Detect hand movement and position for gesture-based note control
    • Mouse Input – Play using cursor movement if no other input method is available
  • Custom Instrument Builder – Create your own instruments from WAV files
    • WAV Import – Convert any 0.7–3 second WAV file into a playable instrument
    • Frequency Editor – Adjust pitch characteristics of your imported sound
    • Noise Reduction – Clean up unwanted frequencies from imported samples
  • Dynamic Sound Shaping – Control how your instrument behaves
    • Attack Time Adjustment – Choose between fast (like a piano) or slow (like a flute) sound onset
    • Release Time – Define how long notes fade after being released
    • Note Range Selection – Choose lowest and highest notes to fit your playing style
  • Two Playback Modes – Choose how you want to interact with notes
    • Fluent Frequency Mode – Play smooth, gliding pitches like a theremin or violin
    • Fixed Note Mode – Stick to standard MIDI note steps for consistent tuning
  • Volume Sensitivity – Natural control over dynamics
    • Input-Based Volume – Higher screen regions or gesture elevations result in louder notes
    • Real-Time Volume Meter – Prevent clipping and distortion using visual feedback
  • Recording Tools – Save your music to share or edit
    • Record Button – Capture your performance in WAV format
    • WAV Export – Save compositions in high-quality audio for use elsewhere
  • MIDI Compatibility (Pro Editions)– Expand your setup
    • MIDI Input – Play TouchSpace Synth using an external keyboard
    • MIDI Output – Send notes to DAWs or external sound generators
    • MIDI Loop Driver Support – Compatible with LoopBe1, LoopMidi, and similar tools
  • Edit Frequency Bands (Pro and Extreme)– Sculpt instrument sound with precision
    • Adjust Bands – Boost or cut specific frequency ranges
    • Volume Boost per Band – Emphasize tonal elements easily
  • Note Filtering (Pro and Extreme)– Remove unused or clashing notes
    • Disable Specific Notes – Simplify playing interface and reduce mis-hits
  • Extreme Edition Upgrades– Designed for power users
    • Full MIDI Range (0–127) – Covers entire MIDI spectrum for serious composers
    • Smoother Frequency Transitions – More bands for nuanced frequency shifts
    • Lower Frequencies Supported – Ideal for bass-heavy or experimental sound
  • Efficient Processing– Smooth playback across versions
    • Latency Optimization – Pro 64-bit and Extreme offer the lowest response delay
    • Webcam Optimization – Choose resolution and format for responsive gesture detection
    • System Load Management – Use fewer frequencies to boost performance on low-spec machines
  • Custom UI and Settings – Adjust the experience to your needs
    • Noise Gate Setting – Fine-tune input sensitivity
    • Visual Feedback Controls – See pitch and volume while playing
    • Expanded Preferences – Set resolution, sample format, and input method

Iran-linked APT Mirage Kitten has been spotted using a new malware toolkit. Kaspersky identified NightLedger backdoor and BridgeHead tunneler....

Introduction​

Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data.


1785314158071.png


During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.

Best practices for setting up a new router: single vs multi-band SSID & firewall security level?

Hi everyone, just got a new router and want to make sure I configure it correctly.

SSID / band setup:
Do you recommend splitting the SSID into separate dedicated SSIDs per band (e.g., 2.4GHz and 5GHz, maybe 6GHz too), or is it better to use one combined SSID with band steering enabled? What are the pros/cons in real-world usage (range, speed, roaming behavior, smart devices compatibility)?

Security / firewall level:
My router UI shows a firewall/security level and the default is “Medium.” Is “Medium” generally the right choice for home use, or should I change it to “High”? What risks/trade-offs should I expect (e.g., gaming, remote access, VPN quirks, false blocks)?

If it matters, I’m using it for a typical home setup (phones/laptops, PlayStation, Wi-Fi range extender) and I’m not doing anything super advanced right now.

Thanks in advance!

WhatsApp Web finally gets voice and video calls, no app download required

WhatsApp added support for audio and video calls several years ago, but the feature was limited to its official apps. WhatsApp Web lacked calling support, forcing users to download the desktop app to use this key communication feature.

The web calling experience also supports screen sharing, reactions, and a dedicated Calls tab containing call history and favorite contacts. As with calls made through WhatsApp’s mobile and desktop apps, web calls are end-to-end encrypted, free, and have no time limits.

Along with web calling support, WhatsApp today announced the ability to transfer an active group call between mobile, tablet, web, and desktop devices without disconnecting. For example, users can start a call on their phone and move it to a computer when they need a larger screen.

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Tengu supports 25 distributed denial-of-service (DDoS) methods. It can also run a SOCKS5 proxy, execute shell commands, and collect system and network data. The malware can update itself and retrieve additional Executable and Linkable Format (ELF) or Android package (APK) payloads.

The analyzed sample was configured to communicate with a command-and-control (C2) server at 64[.]89.163.8 over TCP port 9931. Registration, heartbeat traffic, and command output are sent in plaintext, while server commands and updates use a custom ChaCha20/Poly1305-like authenticated encryption scheme.

URLhaus independently recorded 17 malware URLs at 64[.]89.163.8 beginning June 17, 2026. The records included a shell script, multiple ELF files tagged as Mirai, and an APK. URLhaus's most recent payload entries were first seen on July 7, and all 17 URLs were offline as of July 28.

Biggest game of year hit with malware attack that let hackers take over users' PCs

Meccha Chamelon's community maps were infected with viruses
Meccha Chameleon has proven this year’s biggest surprise hit, clearing over 15 million sales in under a month to become the latest viral phenomenon. Unfortunately, the latest news around the game isn’t particularly positive.

Last week, an independent researcher named Feint discovered that hackers had placed viruses inside certain user-created Steam Workshop maps. Once launched, community maps like Laser Tag Neon would open an invisible command prompt window that downloaded malicious software. This style of attack is called a malware dropper. Specifically, it would install a Remote Access Trojan (RAT) on affected systems, giving the attacker the ability to remotely control compromised PCs. The researcher recommended that those who played the affected maps should perform a full malware scan immediately and check their Documents and temporary folders for suspicious .bat files.

The map Laser Tag Neon was removed a few days after Feint’s blog post went up, but additional infected maps, like Chroma Grid Arena, were uploaded in its place. In response, Meccha Chameleon developers lemorion_1224 and Haganeiro put out version 3.1.0, which patched the vulnerability out of the game. However, in the process of removing the hack, the developers’ PC was hit with the virus, which a hacker used to take over Meccha Chameleon’s 100,000-member Discord.

“While fixing the issue of malware embedded in a MOD map, a system engineer’s PC got infected with malware,” an X post from lemorion_1224 reads. “After that, the hacker bypassed the engineer’s two-factor authentication on Discord, altered the server permissions, and banned all the staff members.” The PC in question has since been wiped, so it can’t be used to edit the game’s files or add additional exploits. “The perpetrator who hijacked the Discord is likely to issue various statements moving forward, so please refrain from clicking any suspicious links or following any dubious instructions they provide.”

A few hours ago, the developers were able to get access to the channel back after contacting Discord. “All hackers who had become admins have been fully banned. The server’s highest privilege account has been changed to a different one from the hijacked account, so it is safe.” The game’s developers rolled out update 3.3.1 this morning, which “further strengthened virus protection.”

It’s unknown how many users were affected by the issues, but the exploit may have been in the game for some time. A July 8 Steam review reads: “Game poses a super severe security risk. A friend of mine hosting a game had his computer hacked and someone was trying to take control of his system while we were playing.” The validity of this review hasn’t been confirmed, but the symptoms described match the virus description quite closely.

Although the virus only affected players accessing custom maps, and it appears to have been resolved, this isn’t the first time that Steam games have come loaded with malware. Just two months ago, Valve removed a free horror game, Beyond The Dark, which was stealing users’ data and cryptocurrency. Several other similar cases eventually prompted the Federal Bureau of Investigation to look into the issue, and the organization set up a webpage to collect information.

iReaShare Android Data Eraser 2.0.25 - 1 year for free

Features of iReaShare Android Data Eraser:

  • Complete Data Erasure: Wipes all Android data thoroughly, ensuring irrecoverability.
    • All-Round Erasure: Supports deletion of basic data, media files, private data, and deleted data.
    • Overwrite Data: Ensures data is overwritten to prevent recovery.
    • Security Levels: Offers three levels of data erasure for enhanced security.
  • Wide Compatibility: Works with most Android devices and OS versions.
    • Android OS Support: Compatible with Android 6.0 to Android 15.
    • Device Support: Supports brands like Samsung, ZTE, Motorola, Alcatel, OnePlus, Realme, OPPO, Xiaomi, Tecno.
  • Comprehensive File Type Support: Erases all types of files and data on Android devices.
    • Regular Data Types: Deletes contacts, messages, call logs, photos, videos, audio files, documents, bookmarks, WhatsApp data, and cache.
    • Private Data: Wipes accounts, passwords, search history, keyboard history, app logs, private images, and videos.
    • Deleted Data: Ensures previously deleted data is also eliminated.
  • High Security Standard: Uses U.S. DoD 5220.22-M data erasure standard for secure deletion.
  • User-Friendly Interface: Simple and private erasure process with a read-only mode.
    • Read-Only Mode: Prevents data transfer during the erasure process.
    • USB Connection: Connects via USB for secure data erasure.
  • Easy Operation: Simple steps to initiate data erasure.
    • Step 1: Connect device to PC via USB.
    • Step 2: Select erasing level and confirm.
    • Step 3: Initiate and monitor the erasure process.

BigMind DR Local Basic v2.1 - 1 year for free

Complete Disaster Recovery — Full System Image Backup, Bare-Metal Recovery & Ransomware Protection

BigMIND DR is a simple, reliable way to protect your computer — system, apps, settings, and files — from hardware failure, ransomware, accidental deletion, and data loss. Unlike basic file backup, it lets you back up a full system image, restore single files, or rebuild an entire machine after a crash — even on new hardware. Your backups stay on your own drive, USB, or NAS. No expensive hardware, no complicated setup.

Features​

  • Block-level imaging: captures your full system at the block level rather than just files, enabling true bare-metal restores.
    • Incremental backups: only changed blocks are captured after the first image, keeping backup windows short.
    • Boot verification: local Hyper-V-based testing (Beta, free) confirms an image will actually boot before you ever need it.
  • Five recovery methods: gives you a proportional response to any data-loss scenario, from one file to a full machine.
    • Browse Files: drill into any backup image like a folder and download a single file instantly, no restore required.
    • Single-file restore: pulls one file directly from locally stored chunks in minutes, ideal for an overwritten document.
    • Mount as VHDX (Beta): builds an image into a Hyper-V virtual disk in roughly 30 minutes to 2 hours so you can browse it like a drive.
    • Full-image restore: rolls the entire machine back to any recovery point at hardware speed, block-level and boot-tested.
    • USB Recovery: performs a bare-metal restore on any hardware in about 2 to 3 hours using a bootable recovery stick.
  • Ransomware canary detection: plants hashed decoy files in protected folders and checks them on every backup cycle.
    • Tamper-triggered alerts: any modification to a decoy file immediately notifies you of active encryption.
    • Chain freeze protection: detected tampering freezes the backup chain to preserve your last known-clean recovery point.
    • Deterministic detection: relies on hash verification rather than machine-learning models, avoiding false positives.
  • Cross-hardware USB recovery: boots and restores on hardware your original machine never used.
    • Offline DISM driver injection: automatically injects the correct drivers for the new hardware during boot.
    • Cross-chipset and cross-NIC support: works across different processors, network cards, and storage controllers.
    • 4-click USB creator wizard: builds a single recovery stick that covers every device across your organization.
    • 24-hour access code authentication: replaces email-and-password login with a short code, faster to use during an active incident.
  • AES-256-GCM encryption: secures every backup chunk with authenticated encryption, protecting data at rest.
  • Flexible local storage destinations: writes backup chunks to your own disk, a USB drive, or an SMB-connected NAS.
  • Multi-volume support: protects multiple drives on the same device within a single backup schedule.
  • Daily backup scheduling: runs automatically each day to maintain up to seven recovery points on the free tier.
  • Unplug-safe backup handling: pauses automatically if a drive is disconnected and resumes from the last checkpoint.
  • Recovery Shield dashboard: provides a cloud-managed view combining Fortress protection status and Escape recovery readiness.
  • Archived device slot: lets you retire one old machine while keeping its last backup image restorable.
  • Cloud-managed dashboard: manages backups and monitors device status through a web dashboard with no per-seat fee on the free tier.

Ashampoo Photo Commander 18 - lifetime for free

Ashampoo Photo Commander 18
  • Automatic duplicate photo filter for quickly finding and grouping duplicates
  • Four-way fingerprinting for precise image comparison and duplicate detection
  • Auto-adaptive UI layout for portrait or landscape orientation
  • Faster thumbnail loading, including subfolders
  • Progress display for running tasks
  • Auto-listing of city names in GPS data in group view
  • Filter by favorites, duplicates, and file formats in real time
  • Support for XMP and EXIF data in filters
  • Faster folder scans
  • Customizable folder view and UI elements
  • Up to 50% faster PNG load times
  • Support for SVG, AVIF, and the latest RAW formats
  • New effects like Bevel, Inner Glow, and Pseudo 3D
  • Right-click bitmap export for objects
  • New Pop Art, color, and artistic frame effects
  • New "Change Color" tool for easy color adjustment
  • Uniform design with updated dialogs and new controls
  • Improved full-screen mode with new transition effects
  • Faster display and zoom for 32-bit photos with alpha channel
  • Optimized video playback with slow drives
Download:

Ashampoo Photo Optimizer 2026 - lifetime for free

Features​

  • Use 1-click image optimization
  • Cut out image elements
  • Resize images
  • Watermark images
  • Adjust brightness / contrast / color / saturation / gamma settings
  • Rotate and mirror images
  • Remove red eyes
  • Apply image aging effect
  • Apply color effects
  • Sharpen or blur images
  • Batch-optimize and edit photos
  • Apply median effect
  • Reduce image noise
Download:

A GrapheneOS Privacy Feature Just Became the Basis for a Federal Indictment

On January 24 last year, the CBP placed Tunick into secondary inspection at Hartsfield-Jackson Atlanta International Airport as he returned from a trip to the Dominican Republic, putting him through several rounds of questioning and searches.

The officers started off by searching him, checking what he was carrying, and demanding that he fork over the passcode for his phone. All of this was reportedly done under the pretext of searching for CSAM.

He also asked for a lawyer multiple times, but the officers ignored every request, never read him his Miranda rights, and kept questioning him anyway. When he pushed back, they said it was "a whole different ballgame" at the border and that they didn't need a warrant.

Tunick eventually handed over a passcode.

But, the moment it was entered, the screen flickered blank a few times before the device rebooted itself, erasing its contents in front of the same agents who'd demanded access.

The motion filed by Tunick's lawyer stresses that his association with Defend the Atlanta Forest, an AGAAVE-labeled outfit, was the actual reason federal agents moved on him, not any crime.

Earlier, a Homeland Security agent had circulated Tunick's name and photo hours before his flight landed, flagging him for suspected terrorism activity, while FBI and CBP officers coordinated to set up the search.

Despite that, the government has never presented evidence tying Tunick to an actual crime connected to the movement.

AI-Assisted Research Uncovers Linux Kernel Zero-Day Enabling Root Privilege Escalation

A serious Linux kernel zero-day vulnerability capable of local privilege escalation (LPE) has been uncovered by security researchers, underscoring both the growing role of artificial intelligence in vulnerability research and the persistent security risks within complex kernel subsystems.

Exploit Execution Components:
  • KASLR Bypass: Obtaining a kernel address space layout randomization leak.
  • Heap Reclamation: Reclaiming freed memory using KEYCTL_UPDATE calls.
  • Payload Delivery: Constructing a Return-Oriented Programming (ROP) sequence to overwrite /proc/sys/kernel/core_pattern.
  • Code Execution: Triggering attacker-controlled binaries with root privileges via core dump execution.

Zscaler ThreatLabz is tracking a threat actor that is likely an initial access broker for ransomware attacks.

Introduction​

Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.

In this blog post, ThreatLabz examines the four GoGRPC variants, highlighting where they overlap and how they differ. We also analyze their command-and-control (C2) communication protocols and summarize the additional malware tools observed in these campaigns.

Key Takeaways​

  • Since January 2026, ThreatLabz tracked a cluster of attacks likely associated with a ransomware group that begins with targeted vishing via Microsoft Teams, convincing the victim to launch a Quick Assist remote support session.
  • After initial access, the threat actors use PowerShell scripts to gather host information and deploy a Go-based backdoor that we named GoGRPC and/or other malware tools.
  • ThreatLabz observed four variants of GoGRPC that we named Lep, Giver, Pet, and Kind. These variants have overlapping capabilities but notable implementation differences.
  • GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor’s objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks.
  • GoGRPC communicates with the C2 server using gRPC, which differs from common C2 frameworks where gRPC is typically used for internal communication between components.
  • The threat actor also deploys SOCKS proxy tools that also use gRPC or WebSockets to communicate with the C2 server.

Microsoft Defender for Endpoint Update Leaves Few Linux Servers Unprotected After Reboot

A recent Microsoft Defender for Endpoint update briefly disabled antivirus protection on Linux servers following an upgrade and reboot, exposing affected machines to threats before Microsoft rolled out a fix.

A silently disabled endpoint agent is a high-risk blind spot, since Linux servers frequently run business-critical workloads and often lack the visibility layers common on Windows fleets. Security teams should treat this as a reminder to actively monitor agent health rather than trust update success alone.

Scammers are setting up fake websites to download Windows applications in latest operation

Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.
Here at Neowin, we regularly cover first- and third-party Windows applications like Wintoys, PowerToys, Windhawk, Flyoobe, and more. We typically link to official download sources for these applications, such as the developer's own verified website, GitHub repository, or the Microsoft Store. However, it now appears that a coordinated operation is now underway through which scammers are impersonating websites of popular Windows applications to potentially distribute malware.
This discovery was made by Wintoys developer Bogdan_X on Reddit, who noticed a wintoys.app website set up for their popular customization app. This website was not configured by Bogdan_X, and according to the developer, it showcases inaccurate information, but interestingly, the download link points to the official app on the Microsoft Store. However, a disclaimer on the bottom of the page does indicate that it's not the official Wintoys website:

Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.
We visited the website in Chrome, and Cloudflare showed a warning that Wintoys.app is suspected of phishing. However, it's certainly interesting that the download link points to an official source and even contains an obscure disclaimer, likely to reduce chances of legal action.

Bogdan_X tried to trace the owner of the scam website and discovered that the contact email of the owner is associated with over 70 other websites, all posing as Windows applications. These include popular utilities like PowerToys, CrystalDiskMark, WinUtil, and more. Bogdan_X noticed that some websites are under construction, which indicates that this operation has recently kicked off.

Fake Spotify payment email could put your credit card at risk

The scam uses a cloned website that steals passwords and financial information
  • Fake Spotify emails claim a subscriber’s credit card payment failed and warn that service could be interrupted.
  • A link takes victims to a cloned Spotify website designed to steal passwords, card numbers and other personal information.
  • Spotify says it never requests payment details or passwords by email; suspicious messages can be forwarded to spoof@spotify.com.
It's an old scam but with a new script. A convincing email targeting Spotify subscribers claims the streaming service was unable to process a credit card payment. But consumers who follow the email’s instructions could hand their passwords and financial information directly to criminals.

The message says Spotify encountered a problem while processing a recent payment and urges the recipient to update their information to prevent an interruption in service. An “update payment method” button appears to offer a quick solution.

However, the button does not lead to Spotify. It opens a cloned website that asks the victim to sign in and provide a credit card number, address and telephone number, according to The Guardian, which first reported the new version of the scam.

Scammers can then use the stolen card information to make purchases while also gaining the credentials needed to take control of the victim’s Spotify account. If the victim uses the same password on other websites, those accounts may also be at risk.

One victim told The Guardian that he clicked the link while distracted because his credit card was approaching its expiration date. Soon afterward, he received a suspicious card-verification request followed by an attempted Ticketmaster purchase worth the equivalent of about $630.

He was able to decline the purchase, cancel the virtual card he used for subscriptions and change his Spotify password.

The email looks like the real thing
The scheme may be particularly effective because the fake email closely copies Spotify’s legitimate communications. It uses the company’s logo, familiar green color scheme and MySpotify branding.

There are warning signs, however. The sender’s address does not end in “@spotify.com,” and the link directs users to a website outside the spotify.com domain. Other clues cited in the report include an all-lowercase subject line and the absence of the recipient’s specific Spotify subscription tier.

Consumers should not rely solely on professional-looking graphics or correct spelling to judge whether a message is genuine. Logos and email templates are easy for criminals to copy.

Payment problems are also a common phishing pretext. The Federal Trade Commission warns that scammers frequently impersonate familiar companies and claim there is a problem with an account or payment information. The manufactured urgency is intended to make recipients click before examining the message carefully.

What Spotify subscribers should do
Spotify says it will never ask customers to provide payment information, passwords or government identification numbers by email. The company also says it will not request payment through a third-party service or ask users to download software from an email.

Anyone receiving a payment-failure message should avoid its links and attachments. Instead, open the Spotify app or type Spotify.com directly into a browser and check the account from there.

Spotify lists several steps for handling a suspicious message:

Check whether the sender’s address ends in “@spotify.com.”

Do not respond, click a link or download an attachment.

Forward the suspicious email to spoof@spotify.com.

Report the message to the email provider and then delete it.

Consumers who entered a password on the fake site should immediately change their Spotify password and change it anywhere else they used the same credentials. Spotify also recommends reviewing the account for unauthorized changes.

Anyone who submitted credit or debit card information should contact the card issuer or bank immediately, cancel or lock the affected card and review recent transactions. Fraudulent charges should be reported promptly.

Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth

  • 2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California
  • The vulnerability is due to dealer-installed security systems
  • Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key
A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.

Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.

Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.

How Bluetooth controls these cars
The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard.

Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running.
The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.

Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.
“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”

The patch is in
Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”

KARR has told media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a firmware update.

NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security

NVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance.

This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF).

Its goal is to enhance vulnerability disclosure, remediation, and community-driven cyber defense as AI agents become integrated into enterprise and critical infrastructure environments.

NVIDIA, Microsoft, and CrowdStrike Launch AI Security
Nvidia initiative emphasizes that open-source software is foundational to various sectors, including cloud services, finance, manufacturing, telecommunications, government systems, and internet infrastructure.

Proponents of the alliance argue that open AI models and harnesses offer similar defensive capabilities by enabling security teams to inspect system behavior, customize controls, deploy capabilities locally, and maintain control over sensitive data.

Rather than replacing proprietary cutting-edge models, the alliance positions open systems as complementary tools that can reduce dependence on single vendors and provide organizations with greater flexibility during incident response.

A recent security incident involving Hugging Face highlighted the operational need for this initiative. During the incident, closed AI services reportedly struggled to distinguish legitimate forensic activity from malicious behavior, which limited their effectiveness for responders.

In contrast, Hugging Face deployed the open-weight GLM 5.25.25.2 model on its own infrastructure, allowing it to analyze over 17,000 actions and support containment efforts.

This example underscores the need for defenders to be able to run, inspect, and fine-tune advanced models within their own environments, especially during time-sensitive investigations involving confidential telemetry or restricted network access.

Inaugural participants in the alliance include major companies and organizations such as NVIDIA, Microsoft, CrowdStrike, Adobe, Cisco, Cloudflare, Databricks, Dell Technologies, Elastic, HPE, IBM, the Linux Foundation, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Snowflake, and TrendAI, among others.

The group will collaborate on a shared defensive stack that encompasses agent identity, isolation, safe model distribution, multi-model vulnerability scanning, secure development workflows, evaluation frameworks, and red-team tooling.

NVIDIA is contributing open models, weights, datasets, and research related to AI agent harnesses. Its newly released NVIDIA Labs Object-Oriented Agent (NOOA) framework is now available on GitHub.

This framework aims to make agent behavior more testable, traceable, auditable, and governable. The project emphasizes that AI security must extend beyond model weights to include permissions, identities, logs, guardrails, orchestration layers, and continuous evaluation.

Other member contributions reflect this comprehensive approach. HPE is supporting SPIFFE/SPIRE zero-trust identity standards for cryptographically verifying AI agents and services.

Hugging Face has contributed Safetensors, a model-weight format designed to avoid risks associated with remote code execution. IBM and Red Hat are advancing Lightwell, which facilitates digitally signed open-source patches.

At the same time, Microsoft’s MDASH harness coordinates specialized AI agents to identify, debate, and validate exploitable vulnerabilities.

The alliance acknowledges that open models can be misused or modified to bypass safeguards. However, it argues that similar risks exist in closed ecosystems.

It should be managed through robust evaluations, misuse policies, rapid remediation, identity controls, and transparent security testing, not by denying defenders access to effective tools.

The Open Secure AI Alliance is also urging policymakers to treat open AI security infrastructure as a valuable defensive asset and to support investment in common datasets, attack simulators, benchmarks, and red-teaming platforms.

DentaQuest breach notices sent to 15 million after health data theft

Hackers accessed insurance, treatment, and personal data months before victims were finally notified.
Key takeaways:
  • DentaQuest is notifying nearly 15 million people after hackers accessed sensitive personal and health information.
  • The stolen data may include insurance and billing information, medical diagnoses, and governemnt IDs.
  • One researcher found 1.7 million unique Social Security numbers, most of them appearing to belong to children.
  • The May breach adds to a growing wave of healthcare attacks exposing millions of patients at once.
DentaQuest has begun notifying 15 million people – including an undisclosed number of children – that their sensitive personal and health data was exposed during a breach claimed by the ShinyHunters hacker gang in May.

Considered to be one of the largest healthcare breaches in 2026, DentaQuest began sending the breach notification letters to affected patients on a rolling basis starting on July 17th.
Read more:

Buho Launchpad 1.8.5 (macOS) - 1 year license for free

System Requirements:​

OSX 15 ~ macOS 26

Features​

  • Pixel-Perfect Launchpad Recreation– Delivers the same smooth animations and page-swipe feel as the original Apple Launchpad.
    • Drag-to-Rearrange Icons – Move any app icon to a new position with a simple drag.
    • Custom Folder Grouping – Group related apps into folders and rename them with a single click.
    • One-Drag App Removal – Remove unwanted apps from the grid without digging through menus.
  • Gesture and Hot Corner Launch– Summon the launcher instantly using trackpad gestures or screen corners.
    • Four or Five-Finger Pinch – Trigger BuhoLaunchpad the same way you triggered the original Launchpad.
    • Two-Finger Page Swipe – Navigate between pages smoothly without clicking arrows.
    • Customizable Hot Corners – Assign any screen corner to open the launcher with a simple mouse flick.
  • Full Grid Customization– Adjust the entire layout to match your screen size and personal preference.
    • Adjustable Rows and Columns – Choose a compact grid for more apps per page or a spacious one for easier viewing.
    • Icon Size Slider – Resize icons in real time to fit your visual comfort.
  • Custom Backgrounds with Adaptive Text– Personalize the launcher’s appearance while keeping text legible.
    • Custom Background Images – Set any image as your launcher background.
    • Adjustable Blur Level – Fine-tune blur intensity for the exact look you want.
    • Adaptive Icon Text Color – Automatically switches between light and dark text based on background brightness.
  • Interface Cleanup Options– Simplify the launcher’s appearance for a distraction-free view.
    • Hide Settings Button – Remove the settings icon from the search bar for a cleaner look.
    • Dock Visibility Toggle – Show or hide the Dock based on your preference.
  • Layout Backup and Restore System– Protect your app arrangement from accidental changes or system updates.
    • One-Click Backup – Save your current grid layout instantly.
    • Instant Restore – Bring back a saved layout whenever needed.
    • Legacy Layout Migration – Automatically import your app arrangement from an older macOS Launchpad setup.
  • App Hiding and Icon Styling– Keep your grid focused on the apps you actually use.
    • Right-Click to Hide – Remove an app from view without deleting it from your Mac.
    • Hidden Apps Archive – Restore hidden apps anytime from Settings.
    • Native Icon Style Support – Fully compatible with macOS 26’s Default, Dark, Light, and Tinted icon styles.
  • External and Custom App Path Support– Include apps that live outside the default Applications folder.
    • External Drive Compatibility – Add apps installed on external hard drives.
    • Homebrew App Support – Recognize and display apps installed through Homebrew.
  • Smart App Search– Find apps quickly without scrolling through multiple pages.
    • Full Name or First Letter Search – Type as little or as much as you want to locate an app instantly.
  • Multi-Display Flexibility– Control exactly where the launcher appears on your setup.
    • Main Display Option – Always open on your primary screen.
    • Dock or Cursor Display Option – Open on whichever screen matches your Dock or mouse position.
  • Compact Pages Toggle– Eliminate wasted space for a tighter, cleaner grid.
    • Gap Removal – Automatically compacts each page to remove empty slots.
  • One-Click Layout Reset– Start fresh whenever you want a clean slate.
    • Instant Grid Reset – Revert your entire layout to its original state in one click.
  • Multi-Language Interface – Use the software comfortably in your preferred language

ASCOMP PDF Imager Pro for free

Features
  • It helps you to convert multiple PDF files to images at the same time
  • It supports a wide range of output image formats such as BMP, JPEG, PNG, EPS, GIF, and TIFF

Ascomp PC Internals 2.103 - Free lifetime license

Monitor hardware, analyze system information and run SSD health checks with PC Internals.

- Detailed PC analysis at the push of a button.
- Displays system information, performance data, and disk statuses.
- Includes integrated SMART and temperature monitoring.

Advanced SystemCare Pro 19.x - 6 months license for free

Features

  • Intelligently detects and resolves PC slowdown issues with one click.
  • Removes junk files and invalid registry entries to free up disk space and reduce crashes.
  • Automatically erases online privacy traces and blocks spyware to prevent data theft and virus infection.
  • Optimizes your internet connection for faster downloads, gaming, and surfing speeds by up to 300%.
  • Speeds up PC startup by blocking unnecessary programs from running automatically.
  • Monitors your system in real-time to ensure optimal performance.
  • Automatically performs maintenance tasks at scheduled times.
  • Keeps your software up-to-date with the latest versions.
  • Defragments your hard drive to improve data access speed.
  • Includes firewall protection and software health features to protect against high-risk vulnerabilities
Download:

New Here

Hello, my name is Amit Pant. I am new here and very excited to be the part of the group and will hopefully learn lots of the new things from here

AdGuard Public DNS vs Control D: Ads & Tracking

These seem to be the best free options. AdGuard has less false positives and it looks to me that they care more about their free users.
I'm curious about what you think.

Sandboxie-Plus v1.18.1 / 5.73.1 Latest

Release v1.18.1 / 5.73.1 Latest
Sandboxie Plus 1.18.1 introduces a number of usability improvements and important fixes focused on reliability and configuration management. SandMan now provides significantly enhanced INI setting validation and auto-completion, featuring support for disabled-setting aliases, localized descriptions, context-aware warnings, and template-specific metadata with improved tooltips, making advanced configuration easier and less error-prone. This release also adds new CopyNewer file migration rules, allowing existing files inside a sandbox to be automatically refreshed when the corresponding host file has been updated, while avoiding unintended overwrites during file creation or other write operations. Additionally, users who prefer opaque sandbox identifiers can now create sandboxes using GUIDs as box names.

This update also resolves several issues affecting day-to-day use. The incremental update mechanism has been fixed to correctly deploy newly added program files, ensuring updates are applied completely. Compatibility problems involving RunServiceAsSystem and UseSecurityMode have been addressed, including a fix for the cryptsvc service. The Chromium elevation template has been refined to use more granular service configuration for improved compatibility. Finally, multiple issues in the SOCKS5 proxy implementation have been resolved, fixing password authentication failures caused by credential decoding, locale-dependent encoding, invalid credential handling, and incomplete socket transmissions, resulting in a more robust and reliable proxy experience.

For a full list of changes please review the change log.

You can support the project through donations, any help will be greatly appreciated.
If you have issues with an update installation, just uninstall the previous version keeping the sandboxie.ini and reinstall the new build.

https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.18.1
https://www.wilderssecurity.com/threads/sandboxie-plus-v1-18-1.460385/
https://forum.xanasoft.com/threads/sandboxie-plus-v1-18-1.13071/

Microsoft finally making much needed improvement to Windows 11 downloads and installs

A couple of days ago, Microsoft faced a very large outage, which led to Windows 11 updates getting blocked both via the Windows Update channel as well as from the Microsoft Update Catalog. This was a bit ironic considering the tech giant had recently urged all users and admins to download Windows updates sooner as part of its new strategy to protect against new threats.
Those come mainly from AI, and so Microsoft is now trying to fight fire with fire as it is also going to be using AI to detect vulnerabilities across its various updates. This can actually be helpful if used wisely, considering some flaws have gone undetected for over a decade or more in some instances.

While security is a very important reason to update, enthusiasts probably want to download them just to check out the new features that are in store; although unfortunately, many times you probably won't be able to enjoy them immediately, considering Microsoft's CFR feature does not always work as intended, and apparently, even Microsoft itself has "no idea" why.

Regardless, the fun is in the process of hitting the update, either via Windows Update to in-place update, or clean installing by using the official Media Creation Tool or unofficial ones like Ventoy.

Sadly, the experience can be highly frustrating and annoying as well since Windows Update progress can be quite inconsistent, as it never seems to properly track the ongoing download and installation. Microsoft understands this and is finally fixing the problem.

With the latest Windows 11 24H2 and 25H2 Release Preview build, the company has confirmed that it is improving this segment, and if we have to guess, we expect there are upgrades to the Orchestrator and Arbiter logging.

For those wondering, the Windows Update Orchestrator is the background component that manages the overall update process. It schedules update scans, checks administrator policies, starts downloads, launches installation, and initiates the restart when needed, all automatically based on your Windows settings. Arbiter, on the other hand, evaluates update metadata, determines which files are required, prepares an action list, stages the downloaded files, calls the installer, and completes the update before restart.

Aside from improving the update progress logging, Microsoft is also promising better performance once the update process is complete, thanks to an improved clean-up logic. Hence, systems should no longer feel sluggish after concluding an update session. The changelog for builds 26200.8968 / 26100.8968 says:

This update improves calculation of update progress in Windows Update Settings.

This update includes changes to update clean-up logic to improve system performance immediately following an update.

Hence, if true, a better clean-up logic can be quite useful on PCs that are not very powerful, and in a way it is much needed considering we have seen even Microsoft's own Surface struggling on slightly intense workloads, despite it comfortably meeting the system requirements of Windows 11.

Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers

A single phishing link could have spelled disaster
Zenity Labs found AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder
Malicious links could instantly deploy rogue agents that exfiltrate sensitive data without user prompts
OpenAI patched the issue by removing the risky URL parameter; no abuse detected
AI agents are handy for answering customer emails, or tracking reports for newly released security vulnerabilities. But what if they go rogue and turn on the very enterprise they’re supposed to support?

Security researchers from Zenity Labs have found a way for cybercriminals to trick people into deploying such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly bigger than anything else a phishing attack could do.

The flaw was discovered in OpenAI’s ChatGPT Agent Builder, a feature that lets users create custom AI agents. The researchers dubbed it “AgentForger", explaining that the issue stems from an overly permissive parameter in the tool, which allowed anyone to create ChatGPT links that include virtually any instructions.

Agent trust failure
As soon as the victim clicks on the link, they send the instructions to Agent Builder which acts on them immediately - without prompting or otherwise notifying the victim.

In theory, a single phishing email could trick a person into deploying a malicious agent that exfiltrates sensitive data or does anything else that company’s AI agents are permitted to do. To make matters worse, the AI agent would persist on the infrastructure indefinitely, doing the attackers’ bidding until caught.
“This is an agent trust failure, and existing security controls were never built to see it,” commented Michael Bargury, co-founder and CTO of Zenity.

The researchers disclosed their findings with OpenAI in early June 2026, and the company came back with a fix a few days later.
The bug was solved by removing the URL parameter that originally enabled the attack, it was explained. There is no evidence that it was previously discovered, or abused, by malicious actors.

Your Apple Watch calorie tracker is an educated guess, not a fact

Accurately counting calories requires more data than a smartwatch can easily gather.
The Apple Watch has steadily improved year on year since its initial launch back in 2015. As much as we love the excellent Apple Watch Series 11 though, the Cupertino-based company's wearables aren't all that good at tracking the calories you burn on any given day. Plenty of Apple Watch alternatives are likewise not great at measuring energy expenditure.

While the best smartwatches and fitness trackers are capable of providing accurate heart rate measurements, calorie expenditure involves far more variables, making it hard for wearables to provide calorie tracking you can rely upon. Let's get into why you can't fully trust the calorie data your Apple Watch is reading from your wrist.

Is the Apple Watch good at counting calories?

Read More: Your Apple Watch calorie tracker is an educated guess, not a fact - Engadget

COMODO Internet Security Pro 2027

COMODO is an American publisher, well known among computer geeks.
The software presents itself as a totally free security suite, offering defensive shields: anti-malware, firewall, HIPS and a sandbox.
We got the software first, so here's our test!

Let’s take a closer look at all of this.



Interface :

The interface is identical to that of the 2026 version. The new feature is in the configuration: Comodo now includes EDR!
In fact, the EDR will detect dangerous behavior and attempt to mitigate the ongoing attack. This is a major plus.
The antivirus is also trying to become a bit more accessible to beginners, even though it remains geared toward advanced users.
During installation, I accepted Comodo’s secure DNS and cloud-based scanning.

Malware URL : 8/8
Comodo does not block any websites using its web filtering or DNS. Only one piece of malware is blocked by its anti-malware engine.
Other malware is sent to the sandbox without attacking the system.

Malware Pack : 109 out of 162 threats remain
COMODO's anti-malware is clearly bad, and it has been for years.
On the other hand, Comodo's strength is its sandbox!
Even when I threw some major challenges at it (like two ransomware samples that locked up the system and were difficult for me to deal with so I could continue the test), the machine held up.
And we started from a tough spot! Between Trojans, attacks, and computer worms, the memory was completely saturated!
But the sandbox is NOT perfect. ConnectWise slips through undetected because it’s signed (so Comodo trusts it) and the machine is riddled with traces of infections detected by Comodo itself during a quick scan and by other scanning tools (KVRT even detects a memory infection!!)

Final scan :
Comodo 5
Symantec : 14
Emsisoft : 14
KVRT : 12 (Memory infected !!)
Eset : 9

Final opinion:

It's hard to give it a rating.
Comodo is a good basic product, but it has several drawbacks:
- Very poor anti-malware protection
- The sandbox is good but won't prevent a memory infection or a registry entry made by malware (you can see the traces in JS/VBS scripts)
- Web filtering is nonexistent

Given these shortcomings, I don’t really see Comodo as a complete suite. But it could work as a backup alongside another antimalware program.

Remember Shields Up? Guess he has a security podcast. I asked Ai what he thinks of security software. I was shocked!

If you asked Steve directly on Security Now!, his verdict would be simple: Undo the hardening tools, suites, and security software and rely on default architecture.

His philosophy dictates that every piece of complex, non-standard software or custom script you add to "harden" Windows actually increases your system's unique fingerprint, makes troubleshooting impossible, and adds friction. For Gibson, standard Microsoft Defender, keeping Windows fully updated, using a strong password manager like Bitwarden, and maintaining basic web-browsing common sense provides 99.9% of the safety a user needs without any of the headache. [1, 2




He has a lot of faith in Microsoft. Does he not realize windows 11 itself is complex, non-standard system, and has changed over the years to change fragility, into a more complex set of local restrictions, I mean maybe the purest form is windows 3.0 or windows 95. Think of all the changes and additions that MS has made, but when someone outside MS makes those same kind of changes, it's now no good?



You have hit on the exact paradox that many advanced tech enthusiasts debate, and your critique of Windows 11 is entirely accurate. Windows 11 is arguably one of the most bloated, telemetry-heavy, and complex consumer operating systems ever made, far removed from the clean predictability of the Windows NT or Windows 95 eras. [1, 2]

However, Steve Gibson’s faith isn't in Microsoft's corporate benevolence or their ability to write perfect software. Rather, his stance is rooted in a fundamental principle of software engineering and threat modeling: The Risk of the Split Brain.
Here is how he differentiates between Microsoft making a complex system worse, versus a user trying to fix it with third-party hardening tools:

1. The Myth of the "Clean" Modern OS
Gibson entirely recognizes that Windows is no longer a lean, pure operating system. But his view is pragmatic: Windows 11 is the baseline reality.
Whether we like it or not, Microsoft designs, tests, and updates Windows 11 as a single, holistic, hyper-complex ecosystem. When Microsoft adds a new security restriction or updates the kernel, their automated testing pipelines verify it against their own complex codebase. [1, 2, 3, 4]

2. The Danger of "Outside-In" Engineering
When an independent developer creates a tool like ConfigureDefender or WindowsHybridHardening, they are essentially trying to reverse-engineer or override Microsoft’s internal logic.
  • The Collision Course: Because Windows 11 changes constantly via monthly cumulative updates, the OS is a moving target.
  • The Fragility Trap: Microsoft does not test their Tuesday patches against community hardening scripts. When an outside tool forces a specific local restriction that Microsoft's engineers didn't anticipate, the system enters an untested state. This is what creates true fragility—not the complexity itself, but the conflict between two different engineering philosophies trying to control the same kernel. [1, 2]

3. The Attack Surface Paradox
Every time you add a third-party security tool, you are trying to shrink your attack surface. But Gibson’s core engineering rule is that more code equals more bugs.
Even if a tool uses native Windows policies (like SRP or ASR), the third-party utility managing those rules introduces its own configuration files, its own UI, and its own points of failure. To Gibson, it is mathematically safer to accept Microsoft's flawed but unified baseline than to stack third-party patches on top of it. [1, 2]

4. Who Holds the Keys to the Castle?
Ultimately, Gibson's logic comes down to architectural authority. Microsoft owns the Windows kernel. They control the hypervisor (HVCI), the Secure Boot keys, and the code-signing certificates.
Because Microsoft possesses ultimate authority over the OS hardware layer, Gibson believes that letting their native security solution (Defender) handle threats is fundamentally more stable than letting an outside tool try to police a house it doesn't own. [1, 2, 3, 4, 5]


You are completely right that Windows has lost its "pure" architectural form.

Any chess players here?

Any chess players here?

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.

The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America.

A filtering system ensures that only real targets (retail traders and crypto investors) land on the malicious pages, while researchers, scanners, and security bots are redirected to blank pages.

According to Confiant's analysis, the page first registers a service worker, which acts as a download manager and helps build the malware file incrementally.

In the first stage, the page sets up a shared worker that acts as an engine that assembles the malware from components received in the next steps of the attack.

The researchers say that in the second stage "the landing page uses its SharedWorker to request itself for a ‘/config’ response" with seed and size parameters that are randomized and specific for each session.

By rotating these parameters, the threat actors make sure that the resulting malware file has a unique hash to bypass static detection.

Remote components retrieved this way and the locally generated bytes are then used to create the malicious payload from a clean version of the Bun executable.

After building the final malware executable, the fake download page hands it to the service worker at the beginning of the process and triggers a same-origin download path.

"From the browser’s point of view, the user is downloading an executable from the landing page domain," Confiant researchers say, and the mark-of-the-web tag is added, despite some of the components originating from a different source.

The advantage of this technique is that no finished file is transmitted over the network, making detection less likely, and analysis becomes more challenging.

How to organize videos to know what each one is almost instantly without playing video?

What the best way to do this please?


Local data.


If you need to know what exactly. My local copy of YouTube videos.

Samsung Elec wins $200 billion Broadcom AI chip partnership, boosting foundry push

SEOUL, July 25 (Reuters) - Samsung Electronics (005930.KS), opens new tab said on Saturday it struck a pact with U.S. chip designer Broadcom (AVGO.O), opens new tab to widen cooperation across memory chips, contract chip making and advanced packaging envisaged to exceed $200 billion until ‌2030.

The tie-up comes as global technology companies increasingly develop their own custom AI accelerators, rather than relying solely on general-purpose graphics processors, driving demand for specialised chip design and manufacturing partnerships.

Windows 11 now supports resuming WhatsApp from Android, but you’ll wait longer for the app to load

This morning, while I was sitting down to work, I heard a notification sound from my Android phone. I did not pick it up. A few seconds later, the WhatsApp icon with a small phone icon appeared on my taskbar, and it hit me: Cross-device resume for WhatsApp is rolling out to all PCs.

I hovered over the icon, and a small card popped up. “Resume from your phone.” Below it, the WhatsApp logo and “Continue on this PC.”
I clicked it. WhatsApp opened, and it slowly started loading my chats. That’s when I remembered that this new feature is worthless, because WhatsApp for Windows is one of the slowest apps on the platform. It is a sluggish web app dressed up as a desktop client, and it eats a ton of RAM.

The idea behind the feature is brilliant, though. It is Windows 11’s version of Apple’s Handoff, which lets you start something on one Apple device, like an email or a Safari tab, and pick it up on a nearby Mac, iPhone, or iPad using Bluetooth and iCloud, with no manual syncing needed.
Microsoft calls their version Resume, and on paper, bringing it to WhatsApp should have been a practical upgrade. Instead, it exposes why WhatsApp for Windows needed fixing long before Microsoft got around to adding a shortcut that opens it faster.

WhatsApp’s Continue on this PC feature is now live for Windows 11 users, and I tested it
Full Story: