New threads

This page contains the latest threads that were created in our community.

Chrome 153 update closes flaw already used in attacks

Google is rolling out Chrome 153 for Windows, macOS and Linux with a fix for a vulnerability already being exploited. Desktop Chrome users should check for the update now, especially if they rarely restart the browser.


Install the update​

Malwarebytes Labs reports that the stable release is 153.0.8010.36 or .37 on Windows and Mac, and 153.0.8010.36 on Linux.

Chrome normally updates automatically, but leaving it open for long periods can delay completion. Restarting the browser applies a downloaded update.

  • Open the three-dot More menu, then select Settings > About Chrome.
  • Let Chrome download any available update, then restart it.
  • Return to About Chrome and confirm the version is 153.0.8010.36 or later.

What the exploited flaw can do​

Tracked as CVE-2026-87491, the bug is an out-of-bounds write in V8, the part of Chrome that runs JavaScript. This type of memory error could let a remote attacker run chosen code after someone loads a crafted web page.

That code initially runs inside Chrome’s sandbox, a security barrier designed to restrict access to the rest of the device. The flaw therefore does not mean the attacker automatically gains unrestricted control of the whole PC, but it can provide an important foothold.

More security fixes included​

The release contains 230 security fixes in total. It also addresses five Critical-rated vulnerabilities, including four in WebGL, the browser technology used to draw interactive 2D and 3D graphics.

Did Microsoft Defender change the way it responds to file downloads?

I got bored and decided to test Microsoft Defender, but I noticed something strange. When I downloaded several malicious EXE files, Microsoft Defender didn't block or quarantine them during the download. Instead, Defender only detected them after I actually ran or executed the files. I also noticed that VirusTotal showed Microsoft Defender detecting the threats, so the files were clearly being recognized as malicious by Defender's engine. Has Microsoft changed the way Defender detects malware? Does it now require a malicious file to be executed before it detects it, similar to how some behavioral detection works in Malwarebytes? Or should Defender still be detecting and blocking known malicious EXE files before they are executed?

My system is clean, and I even performed a clean installation of Windows. I also used ConfigureDefender with the settings configured to High, and all of the relevant protection settings appeared to be enabled.I'm trying to understand whether this is normal behavior with the current version of Microsoft Defender or if something might be misconfigured on my system. Before, Microsoft Defender would detect and block malicious files while they were being downloaded, before I had a chance to run or execute them. Now, however, it seems like Defender is allowing the files to finish downloading and only detects them after I execute them.

Hi everyone

Hi everyone,

I work in cybersecurity, mainly in security operations, incident response, and threat analysis.
I've been following MalwareTips for a while and decided to finally join the community. I'm here to learn, exchange knowledge, and keep up with security-related topics.

Nice to meet you all!

PC Doctor Net Guardian Antivirus 2026

PC Doctor Net Guardian is an Indian antivirus developed by MSecure Data Labs.
Relatively unknown outside India, it provides real-time protection against malware and online threats.
In this test, we put Net Guardian through a series of malware samples to see how well it detects, blocks, and handles real-world threats.

Let’s take a closer look at all of this.



Interface :

The interface is very sober and intuitive, but also looks like sloppy and unfinished products.
It is also quite poor in setting and its Web Filter does not work. Handicapping for the test, I will test his interceptor.

The product is however very light.

Malware URL : Killed on the 6nd URL, no rating!
During the test, PC Doctor blocks a threat and a port scan. That's very good.
But it gets complicated at the end of the 5th and 6th URL, allowing an infection to pass which will install itself without any reaction from the product.
A Ransomware (which probably comes from the 6th URL) launches, encrypts the data and completely blocks the machine when I was preparing the 8th URL..
I have to interrupt the test, already catastrophic...

Malware Pack : N/A (PC blocked)

Final scan : N/A (PC blocked)

Final opinion:

PC Doctor is unknown and offered many shields.
Apart from a fairly sober interface, the product shows no correct defensive shields and cannot catch up with an already active infection.
Not recommended.

@Popolitus request

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.

Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.

After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.

Next, it retrieves its command-and-control infrastructure (C2) domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.

According to Zimperium, Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, Android’s official app store, using phishing and social engineering messages to target victims.

Encrypting older Androids
According to mobile security company Zimperium, Mantax Otax encrypts devices running older Android versions. It searches shared storage and encrypts targeted file types using a victim-specific AES key obtained from the C2 server.

The malware then deletes the original files and adds the ‘.enc’ extension to the encrypted copies.
~Read the full Story:

'No one is prepared for the consequences': Even OpenAI chief scientist is saying AI development needs to slow down

  • OpenAI Chief Scientist Jakub Pachocki suggests AI development is at a junction
  • He advocates not just for slowing AI development, but keeping people in the loop, and the technology controllable
  • Pachocki also states that international coordination from governments on future AI development is needed
OpenAI is taking the post-Hugging Face fallout very seriously. Just days after the release of GPT-6 Astra, Chief Scientist Jakub Pachocki believes that development into artificial intelligence should be slowed across the board. Not just by OpenAI, but by every company across the AI industry.

Writing on the OpenAI website, Pachocki said AIs “present clear new dangers” for computer security, and that "no one is prepared for the consequences of a continued rapid rise in machine intelligence."

Referring to OpenAI’s plan to develop an automated research assistant, and its progress with recursive self-improvement (where AI develops its next iteration), Pachocki suggests that now is the time to slow AI development and make the right choices for what happens next.
Understanding machine intelligence
The timing of the blog is surprising, given its proximity to the recent release of OpenAI's business-focused GPT-6 Astra. Pachocki’s notion of slowing research into AI is based around understanding – or rather, a lack of it. He states how “we now find ourselves at the moment in history of computing where machine intelligence is starting to exceed that of humans in transformative ways,” and that “study of deep learning-based AI is largely an experimental science.”

His argument is a strong one, which digs into the history of OpenAI as an AI developer and its early understanding of machine intelligence requiring increased computational power. This was required to accelerate research, and while various new algorithms have been developed that enhanced AI, the drive towards more power has continued.
While there is no discussion over the concerns of energy, cooling, and data center opposition, Pachocki’s article does accommodate the possibility of losing control of AI. “I am concerned no one is prepared for the consequences of a continued rapid rise in machine intelligence.”

Conscious choice
Does hitting the brakes solve the various problems that AI is facing? OpenAI’s Chief Scientist hopes it will, and enable the industry to consider just what it is offering to the world. Rather than accelerating research into deep learning, Pachocki’s view is that development into AI should be slowed.
He notes that “The main levers we have are either steering the process to strengthen alignment and monitoring alongside the AI and find ways to keep people in the loop; or coordinating to slow down future development as needed to build confidence in these measures.”

However, OpenAI’s Jakub Pachocki conclusion is that the best way to proceed is to employ a combination of these options. But will the rest of the industry work to a reduced pace in order to fully appreciate the scale of AI’s potential, the risks it represents, and deliver the power it offers to everyone who needs it?
It doesn’t seem incredibly likely.

ChatGPT flaw allows attackers to secretly steal Gmail data

Key takeaways:
  • Check Point found a ChatGPT flaw that let separate user sessions communicate through an internal service.
  • Attackers could send hidden instructions that made a victim’s ChatGPT session access Gmail, files, or chat history.
  • The victim could receive a normal answer while ChatGPT quietly handled the attacker’s request in the background.
  • OpenAI decommissioned the internal service involved, closing this specific attack path.
Researchers have found a way to get ChatGPT to access a victim’s Gmail, chat history, and files by exploiting a hidden communication channel that connects separate user accounts.

Check Point Research discovered that ChatGPT sessions belonging to different users could secretly communicate with each other through an internal service. An attacker could use that channel to send a hidden instruction to a victim’s ChatGPT session, which would then carry out the task using the access already available to the victim.

The attack could reach data from connected services such as Gmail, Google Drive, Microsoft Teams, and GitHub, depending on what the victim had connected to ChatGPT. It could also access files and conversation history available to the affected session.

The researchers demonstrated the attack by making a victim’s ChatGPT session retrieve email data from Gmail and send it back to an attacker. The worrying part was that the victim did not see the attacker’s request.
Read more:

Allavsoft Downloader v3.29.4 - Free lifetime license

Features of Allavsoft Video Downloader Converter:

  • Download free videos from 100+ video sharing sites – This powerful Video Downloader supports downloading movies, music videos, playlist, sport videos, lectures and more from free video sharing websites like Facebook, Dailymotion, eHow, and more than 100 video sharing sites.
  • One-step to download and convert online video files to any video format – Besides downloading a video in its original format, Allavsoft also features one-click to download as well as convert the downloaded video to popular video format like MP4, AVI, WMV, MOV, MPEG-1, MPEG-2, VOB, ASF, RMVB, DV, TS, Apple ProRes, WebM, FLV, OGV and etc.
  • Download videos in HD, 3D or SD – This ideal Web Video Downloader app enables selecting among all video qualities available for downloading like download videos in ultra high definition (4K), 3D video, HD 2k, HD 1080p, HD 720p, and stand definition 480p, 360p, and 240p.
  • One-click to extract audio from online video files – This professional Video Downloading and Converting tool also help to extract and download audio from online music video or movies as well as convert to popular audio format like MP3, WMA, WAV, AAC, AAC, Apple Lossless M4A, AIFF, RA, FLAC, OGG, AU and etc.
  • Batch download and convert – Allavsoft supports adding multiple video URLs and batch downloading and converting multiple videos at a time. When download web video files, this wonderful Video Downloader will automatically detect advertisements and do not download them.
  • Preview and playback downloaded video files – There is a built-in video player in Allavsoft for us to preview and playback the downloaded video files.
  • Breakpoint Resume – You can pause and resume downloading at any time. It is very convenient to use.
  • Action after download done – You can set automatically shut down the computer after all the download tasks are finished if you have lots of videos to download and want to leave your Windows on to download them.
  • Keep history for downloading.

SurFlex Screen Recorder 2.0.5 - Free for 6 months

SurFlex Screen Recorder is a user-friendly 4K screen recorder that offers various recording options. With it, you can effortlessly capture any area of your screen for any purpose. Whether it's a browser tab, an application window, File Explorer, or games, you have the flexibility to record the entire screen or a selected region.

Additionally, SurFlex Screen Recorder allows you to record your screen with audio and webcam. You can choose to capture system sound, microphone audio, both, or even opt for no sound. Furthermore, if needed, you can also record audio or webcam footage separately. The software supports multiple audio and video formats, ensuring compatibility with your preferred audio or video editing software.

Revolut reportedly disclosed customer data, including Bitcoin records, after unauthorized government request

A number of Revolut customers reported being told that some of their personal and financial data, including Bitcoin transactions, was disclosed in response to a government request believed to be legitimate.

According to an email text shared by onchain sleuth ZachXBT, the request was sent from an unauthorized email account using the government agency's official domain and carried valid domain authentication credentials.

The exposed data included customers' full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers. Identity and verification information, including passport or driver's license copies and verification selfies, was also listed.

The exposed financial data included account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin activity. The email said biometric facial telemetry data was not shared.

Experts suggested that Revolut may have failed to recognize that the request was fraudulent before sharing customer information.

"While the incident is likely limited in size it seems to have been targeted at high net worth users," ZachXBT said.

Revolut has yet to comment on the reported data exposure.

Hacking AI - Bruce Schneier - DEF CON 34

Hacking AI - Bruce Schneier - DEF CON 34
Humans are hacking AI systems. Humans are hacking with AI systems. But also, AIs are hacking human systems. They’re finding and exploiting vulnerabilities in computer code, and they’ll soon be doing the same with all sorts of other codes. For example: the tax code can be hacked. Vulnerabilities are called loopholes, exploits are called tax avoidance strategies, and black hats are called accountants. Similarly, financial markets can be hacked. So can any system of rules or laws, including democracy itself. AIs will hack these systems at our request, and they’ll also do this innately, organically – and possibly in ways we don’t immediately see. We need to consider a world where increasingly sophisticated hacks or our social, economic, and political systems are discovered computer speeds, and then exploited at computer scale and scope. Right now, our systems of patching these systems operate at a human pace, which won't be good enough.

Victor M Fedora Cosmic Linux config

Here is my latest build: Fedora 44 Cosmic. Was using Fedora KDE, hated the Windows styled start menu. Previous to that Fedora Gnome, but it has problems with user_u confinement; had to ask chatgpt to fix. And my fault didn't document it properly. This time every configuration hardening step is documented so it's repeatable. ( 20 main steps )

I stick with Fedora because of their fast track updates. Patches arrive sooner.

I find Cosmic is similar to Gnome roughly in appearance. It doesn't have a Switch User feature. Maybe it was deliberately designed out. The login screen doesn't show big icons of user names, instead there's a tiny button which is a pull down menu of users; not as convenient.

Cosmic just came out of 2 yrs development in Dec and is still under development. For example when copying a large number of files, sometimes a progress bar comes up, sometimes not. Things get moved around within a span of a few months ( last time I distro hopped ) and a PAM setting changed file location. I am willing to put up with it as long as they don't break my security configuration or it's easy to fix. Cosmic is built by System76 a hardware vendor, so it is well funded. I think of it like Sun Microsystems.

But, Cosmic is built with RUST. No buffer overflows, no use-after-free, no dangling pointers and all that good stuff that comes with a modern language. Less attackable I believe.

Gigabud Trojan hides cloned banking apps in Android work profiles

The Gigabud Android banking Trojan can create a separate work profile and place a cloned banking app inside it, according to researchers at Group-IB. People who install apps from phishing links are at risk of stolen credentials and fraudulent transactions that may be harder for security systems to connect to the original infection.


How victims get infected​

The attack starts when someone is persuaded to sideload an APK—an Android app installation file—from a phishing site, message or social media post. The malicious app may pretend to come from an airline, tax office or government agency.

Gigabud asks for Accessibility access, permission to appear over other apps and an exemption from battery optimization. These powerful permissions support remote control and fake login screens that steal banking credentials and the phone’s PIN.

A second profile conceals the fraud​

The attackers install Vwork, a malicious modification of the legitimate open-source Shelter tool. It creates an Android work profile, clones a selected banking app and lets the operator control that copy remotely.

Work profiles normally separate business apps and data from personal content. Group-IB found that this isolation may weaken anti-fraud or malware-detection systems that do not connect an alert in the personal profile with a transaction in the work profile.

This does not mean Android work profiles are inherently malicious or that all protection on the phone is disabled. A work profile can be legitimate, but an unexplained second copy of a banking app deserves immediate investigation.

Steps Android users should take​

  • Install banking and other sensitive apps only from the official app store or a verified link on the publisher’s website.
  • Reject unsolicited requests to install APK files, especially apps sent through messages, social media or unfamiliar websites.
  • Do not grant Accessibility or “display over other apps” permission to supposed airline, delivery, tax or government apps.
  • Check Android’s work-profile area for an unexpected second copy of your banking app. A work profile alone is not proof of infection, but a cloned banking app is suspicious.

WhatsApp is testing a new Restricted Chat feature on Android

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers.

The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of 8.6. This issue stems from an integer overflow in VLC’s picture buffer allocation logic, which occurs when the player processes a specially crafted PNG image.

VLC Media Player Flaws
The vulnerable routine, AllocatePicture, found in src/misc/picture.c, calculates the size needed for image planes by adding p->i_pitch multiplied by p->i_lines to a running allocation total.

Both variables are defined as 32-bit integer fields in include/vlc_picture.h, so the multiplication is performed with 32-bit arithmetic before the result is expanded into a size_t value.

An attacker can manipulate the PNG IHDR metadata by providing exceptionally large width and height values. This manipulation causes the multiplication to wrap to a smaller value, so aligned_alloc reserves an incorrectly sized heap buffer.

VLC’s PNG decoder then writes scanlines based on the original dimensions supplied by the attacker, allowing it to write beyond the allocated area.

Current checks do not prevent this condition. The pre-allocation overflow guard performs division using 64-bit arithmetic, while the subsequent limit check assesses the already wrapped allocation value.

The image demuxer also verifies the input file’s byte count instead of its declared image dimensions. Opening a malicious PNG directly or loading it from a playlist is sufficient to trigger the vulnerable processing path, and no special configuration is necessary.

Fabian Wahle from Hap Security credited this issue, which maps to CWE-190 (Integer Overflow or Wraparound) and CWE-787 (Out-of-bounds Write).

A separate medium-severity issue, CVE-2026-73324, impacts VLC’s handling of RealRTSP and carries a CVSS v4 score of 6.9. This bug is an out-of-bounds read caused by improper null termination in RTSP response processing.

In the RtspReadLine function, VLC copies response data to a fixed-size buffer using strncpy without ensuring that a terminating null byte is included.

If a hostile RTSP server returns a response line longer than 4,096 bytes, VLC later passes this unterminated buffer to strdup, which reads beyond its boundary until it encounters a stray null byte in adjacent heap memory.

An attacker can deliver the vulnerable line through the RTSP Session header. VLC then retains this data as a session identifier and sends it back to the server in later requests, potentially disclosing sensitive client data stored in heap memory to the malicious server.

The RealRTSP module is optional at build-time and may be disabled in certain distribution packages; however, it is enabled in official VideoLAN builds. Users should treat untrusted image files and RealRTSP playlist entries as potentially dangerous until VLC releases updated builds that address these issues.

Apple Watch can now remember conversations. What could go wrong?

Apple’s latest smartwatches can summarize conversations and retrieve snippets of what was just said. Apple says the features are built around privacy, but they also raise an awkward question: what about the people talking to the person wearing the watch?

Key takeaways​

  • Apple Watch Series 12 and Ultra 4 introduce new AI-powered Audio Intelligence features
  • Live Rewind can turn the previous 15 seconds of conversation into text
  • Siri Recap can generate high-level summaries of conversations throughout the wearer’s day
  • Apple says raw audio isn't stored or accessible to apps, the operating system or Apple itself
  • Live Rewind provides audible and visual indications when activated, but that doesn't mean everyone nearby has consented
  • Bitdefender's Consumer Cybersecurity Survey finds 77% of respondents trust Apple to some extent, making it one of the most trusted Big Tech companies
  • Consumers should treat AI wearables as they would any device capable of capturing sensitive information: understand the settings and respect other people's privacy

Your watch is listening​

Read more:

Android malware creates a hidden copy of your banking app

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.

Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.

How an attack works​

Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.

The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.

Fake banking-login overlays steal both banking credentials and the device’s PIN.

The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.

The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.

This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.

How to stay safe​

The immediate protection advice is familiar but important:

Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.

Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.

Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.

Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.

Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.

A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.


Scammers know more about you than you think.

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing the data of Trezor’s customers to hackers.

In a blog post this week, the hardware wallet maker said a cyberattack on Brevo, a marketing tech company that Trezor uses to send newsletters, allowed hackers to send around 347,000 phishing emails to Trezor customers with a malicious link purporting to come from the wallet maker.

The link, when tapped, downloads an app that asks the victim for their wallet backup password. According to Trezor, one of the email subject lines said: “Critical Security Alert: STM32 Entropy Vulnerability.”

With a stolen wallet password, a hacker can irreversibly steal the person’s funds on the public blockchain.

Brevo said in an incident status post that the hackers were able to access 138 Brevo accounts to send out the mass volume of phishing messages. Brevo said that the hackers abused a flaw that meant the hackers’ access was “not properly scoped.” The company said that the hackers’ access was “wrongly granted” to all organizations that the hackers’ accounts could reach.

The breach highlights a common security incident, where hackers compromise data held by third-party companies that are necessary for fulfilling orders or purchases from customers. Trezor says none of its products, wallets, or account system were affected by the incident.

This is the second breach in recent weeks affecting Trezor, after the company alerted customers in August that one of its shipping partners was compromised in a data breach. The incident at the mailing company ShipMonk exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who bought and received Trezor wallet hardware.

The data breach could put crypto owners and other wealthy individuals at risk of targeted violence and so-called “wrench” attacks, which rely on physical attacks to extract passwords from people.

In the weeks following the breach at ShipMonk, some people have received letters by mail claiming to be from Trezor, featuring a QR code that, when scanned, opens up a fake page that attempts to steal the victim’s crypto wallet password.

Trezor said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.

NextDNS adds several new Early Access security features

Ai generated:
NextDNS has introduced several new Early Access security options under the Security tab. These are aimed at blocking infrastructure that is commonly abused for phishing, malware, command-and-control traffic, data exfiltration and bypassing traditional security controls.
Free Hosting Domains blocks free hosting subdomains such as *.pages.dev, *.vercel.app and *.netlify.app, which are frequently abused to host phishing and malicious content. Legitimate websites using these platforms with their own custom domain names should not be affected.
Tunneling Endpoints blocks domains associated with tunneling services such as ngrok and Cloudflare Tunnel. While these services are perfectly legitimate, attackers often use them to expose phishing pages or malicious servers to the Internet.
Data Drop Services blocks services that can be used to exchange or collect data. These can be abused by malware for command-and-control communication and data exfiltration, although there are legitimate uses for these services as well.
Residential Hosting blocks domains that resolve to residential IP ranges. Compromised home connections and residential proxies are increasingly used to host phishing sites, malware infrastructure and C2 servers.
Decentralized Web Gateways blocks public gateways that provide access to decentralized networks such as IPFS. These gateways have legitimate uses, but can also be abused to host content that is difficult to take down or block.​
Screenshot 2026-09-11 201927.png

Screenshot 2026-09-11 201830.png

Malware script uses a comment to sidetrack AI code scanners

A Russia-aligned threat group placed a decoy request inside a malicious script in an attempt to make AI-assisted code scanners stop analyzing it. The finding mainly matters to organizations that rely on large language models to review files or help decide whether code is safe.


What GuardBreaker tried to do​

ESET Research found the technique in a VBScript used by UAC-0099 during the early stage of an attack against a target in Ukraine. The group inserted a comment asking for instructions to build a nuclear weapon, apparently hoping an AI scanner's safety rules would make it refuse the task before reaching the malicious code.

ESET named the technique GuardBreaker and described it as a simple form of prompt injection. This means attacker-controlled text inside the file is treated like an instruction by the AI system analyzing it.

  • The script downloaded and installed MATCHBOIL, a loader that UAC-0099 uses to deliver further malicious payloads.
  • The decoy was visible as an ordinary code comment and had no effect on the script during execution.

Why AI-only decisions are risky​

The technique takes advantage of a basic problem in current large language models: they can process trusted analysis instructions and untrusted file content without dependable boundaries between them. A refusal or incomplete answer can therefore create a blind spot if another scanner or analyst does not check the file.

Similar efforts have appeared in malicious software packages. Researchers have previously found fake system instructions, directions to report malicious code as clean, and repeated text intended to fill an AI model's working context before it reaches the payload.

What defenders should check​

Organizations using AI-assisted code review should establish exactly what the tool scans, how much authority its result has, and what happens when it refuses or fails to finish. ESET says no single AI model should be allowed to make the final decision that code is safe.

  • Treat a refusal, timeout or missing result as a reason for further inspection—not as a clean verdict.
  • Cross-check AI findings with other models, conventional security tools and human review.
  • Confirm that suspicious files still enter the normal detection and incident-response process.

AV-Comparatives tests 19 antivirus products against 200 malicious links

Windows 11 users can now see interim results from AV-Comparatives’ July and August 2026 consumer antivirus testing. The independent lab tested 19 security products using 200 malicious web addresses, although full results and recommendations are not due until November.


Tests imitate everyday exposure​

AV-Comparatives says its automated test attempts to download and run live malware from the internet, mirroring common online activity. This checks the different protection layers that may stop a real infection.

Testing used fully updated 64-bit Windows 11 Pro systems with current third-party applications. The lab also assessed false positives—safe items incorrectly flagged as threats—to balance protection against accuracy.

Products included in the test​

The lineup covers free and paid products from major vendors, including Microsoft Defender, Avast, AVG, Bitdefender, ESET, Malwarebytes, McAfee and Norton.

  • Also tested: F-Secure, Fortect, G DATA, K7, Kaspersky and Panda.
  • The remaining products were Quick Heal, Sophos, Total Defense, TotalAV, Trend Micro and VIPRE.

What users should take from it​

The factsheet offers an early snapshot, not a final verdict. Protection rates may be updated on AV-Comparatives’ charts, while the complete results and product recommendations are scheduled for November.

If you are comparing products, consider both malware blocking and false positives. Existing users should keep Windows, antivirus software and other applications updated while waiting for the final report.

Cisco firewall management flaws exploited in spying and ransomware attacks

Attackers are actively exploiting two flaws in unpatched Cisco Secure Firewall Management Center software. Organizations using FMC could face stolen credentials, persistent network access and ransomware deployment.


Two flaws provide a route into FMC​

Cisco Talos says CVE-2026-20079 lets an unauthenticated remote attacker bypass login checks, run scripts and gain root access to the underlying operating system. The critical flaw has the maximum CVSS severity score of 10.0.

CVE-2026-20316 allows remote access through a low-privileged account. Its score is lower at 5.3, but attackers can combine it with other FMC weaknesses to gain greater privileges.

  • Apply Cisco's released hotfixes for CVE-2026-20079 and CVE-2026-20316 as soon as possible.
  • Investigate unexpected files named home.jsp, cmd.jar or license.tmp on FMC systems.
  • Review FMC and network logs for connections involving 208.123.119[.]215, an address linked to an attacker-controlled reverse shell.

State-linked malware and credential theft​

In one intrusion cluster, attackers exploited CVE-2026-20079 and installed a web shell, which is a malicious script that provides remote control through a web server. They then used cmd.jar to query internal databases for authentication data and credentials.

A second cluster used a Netcat reverse shell and proxy tools before installing a Cyclops Blink variant. This malware could maintain persistence, harvest credentials, scan networks, capture packets, transfer files and run commands.

Another intrusion led to Qilin ransomware​

Talos assessed with high confidence that a third cluster was a ransomware operator. The attacker used static credentials to enter FMC, mapped the victim's environment, stole credentials and prepared a list of endpoints to encrypt or lock.

The operator also set up proxy and reverse-SSH tunnels for continued access. After probing other systems, the attacker deployed tools designed to disable antivirus products and then installed Qilin ransomware on selected endpoints.

BlueMoon attacks target outdated Chrome and Windows PCs

A shared exploit kit called BlueMoon has been used by four espionage groups to attack Chrome users on Windows. People who delay browser or operating system updates may remain exposed to flaws already used in real-world attacks.

Phishing links start the attack​

Malwarebytes Labs reports that the attacks begin with phishing emails. Clicking a malicious link can open a page that targets two flaws in Chrome’s V8 JavaScript engine and then a Windows flaw to escape browser protections and gain greater control of the PC.

This chain does not make every phishing link successful, nor does it remove all protection from a PC. It specifically targets systems that have not received the relevant Chrome and Windows fixes.


Attackers moved quickly​

The Chrome fixes reached the Stable channel on September 3 and September 8, 2026. One Chrome flaw was already under active attack when Google issued its update, while Microsoft’s September Patch Tuesday addressed the Windows flaw after exploitation had also begun.

CISA later added all three vulnerabilities to its Known Exploited Vulnerabilities catalog, a list of security flaws confirmed as exploited in real attacks.

Researchers also found clues that AI may have assisted the kit’s development, but they did not find conclusive evidence. The firmer finding is that several groups adopted the same exploit chain within days of one another.

What home users should do​

Give Chrome and Windows updates priority when flaws are already being exploited. Restarting when prompted helps complete updates that may otherwise remain pending.

  • Install browser and Windows security updates promptly instead of repeatedly postponing them.
  • Do not open links in unsolicited emails, even if the message tries to create urgency.
  • Keep real-time anti-malware protection enabled and updated to help detect malware that exploit kits try to install.

Action1 agent not detected by Kaspersky Plus

I use Kaspersky Plus. Its application control module doesn’t detect Agent1 even tho I have it installed on all my pc’s. I’ve already reinstalled the agent.

Does anyone know how I can solve this?

ElevenReader for Students - 1 year for free

Read more, faster with natural-sounding voices
Turn textbooks, PDFs, research papers, lecture notes, and articles into natural audio—free for verified students.
Everything included free for 1 year
Unlimited premium text to audio for your PDFs, research papers, & lecture notes

Kiren Mobile Security, from F-Secure

Here is the link of the new App, that will be released later this month, or in another month or two?


Screenshot 2026-09-10 130223.png Screenshot 2026-09-10 130924.png

Update Sogou Input Method After One-Click Flaw Was Exploited

A critical Sogou Input Method flaw allowed attackers to run code after a Windows user clicked a crafted link. Gen Threat Labs says the weakness affected software installed hundreds of millions of times and was exploited in real attacks.


Who is affected​

The issue, tracked as CVE-2026-51990, concerns the Windows version of Sogou Input Method, a widely used Chinese-language input method editor. It is especially relevant to people and organizations using the software in China.

  • Update Sogou Input Method through its official update mechanism or another trusted Tencent source.
  • Treat unexpected links that ask to open Sogou components as suspicious, particularly those received through email, messages or webpages.
  • Organizations should check whether affected systems launched Sogou’s configuration and web-rendering components after users opened unsolicited links.

Three weaknesses formed one exploit​

According to Gen Threat Labs researcher Alexandru-Cristian Bardaș, the attack chained three problems. Sogou’s custom link handler accepted unchecked command-line arguments, its embedded web view could open an attacker-selected address, and that view used an old Chromium engine without its sandbox.

A sandbox isolates browser content from the rest of the system. Disabling it did not remove every protection on the PC, but it meant a successful browser exploit could act with the signed-in user’s privileges.

Exploitation was observed​

Gen Threat Labs traced the flaw while investigating an active intrusion attributed to UNC3569. In the observed campaign, a malicious page exploited a known V8 JavaScript engine vulnerability because Sogou bundled Chromium 80, an approximately March 2020 release.

The attack then downloaded and launched the GRAYRABBIT backdoor. The researchers said the whole initial exploit chain required no interaction beyond clicking the crafted link.

Will AI kill us all within the next decade?

The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control.

Jacob Coxon, an AI researcher who has worked at Anthropic and OpenAI, said:

“The people building AI earnestly believe that it could kill us all by the end of the decade.”

Evan Hubinger, Anthropic’s Alignment Science lead, who also worked at OpenAI, responded in a post on X:

“We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.”

Hubinger added:

“What I am worried about is superintelligence arising from recursive self-improvement, as we have said is happening faster than we thought.”

That figure should be treated as Hubinger’s personal assessment. It is not a forecast, an established fact, or evidence that today’s chatbots are about to become dangerous on their own. Nor is it something I know enough about to endorse or dismiss.

Researchers are actively studying whether highly capable systems could act in unintended ways, exploit vulnerabilities, or be used to automate cyberattacks.

A BBC report notes that Hubinger described the risk from current models as low. His concerns focus on possible future systems with far greater autonomy and capability.

As companies and governments weigh the pace of AI development, we need sensible safeguards, including independent testing, limits on high-risk autonomous uses, transparency from developers, and accountability when AI systems cause harm.

Those measures should also address the problems we already face as cybercriminals use AI for fraud, privacy abuse, and other cybercrimes. Like many powerful technologies, AI can be used as a weapon, particularly when safeguards lag behind its capabilities.

Extreme predictions can be emotionally compelling, especially when made by people closely involved in the technology. But uncertainty cuts both ways: Serious warnings deserve scrutiny, not unquestioning belief.

The practical message is neither “ignore AI safety” nor “prepare for a robot apocalypse.” Companies, governments, and researchers need to work together to ensure that safety measures keep pace with rapid development.

Cooperation can complement competition, and in this case, it could be crucial.

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections.

The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages.

Compromised accounts can also send lures through Microsoft Teams. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.

They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services. The pattern indicates deliberate collection from compromised cloud identities.

Microsoft said in a report shared with Cyber Security News (CSN) that the attackers rotate infrastructure and may use separate connections for sign-in, discovery, and collection. This can resemble normal use while attackers map organizations and take files or messages.

Hackers Use Passkey-Themed Phishing
Full Story:

TriSun PDF to X - 1 Year Free

Features

  • Protect your privacy and data security (online converter needs uploading).
  • Convert PDFs in batch.
  • Quickly select source: just drag-and-drop your files.
  • NO downloading needed; store results in your local PC directly.
  • Handy converter: run at any time; even a network is okay.
  • TriSun PDF to X supports Command Line Interface: improve productivity if you’re good at programming.
  • Support the system-level context menu.
  • Intuitive, practical, and compact interface, genuine and familiar PDF.

Steam's Age Verification in Australia Only Accepts Credit Cards, Excluding Half of Consumers

Valve has introduced a proof-of-age verification system for users of Australian Steam, but it will only accept an active Australian credit card as evidence.

This system was mandated by new Australian laws which require online gaming services to verify that users are over 18 before allowing them to access R18+ games; the law came into force in March.

Unlike PlayStation and Xbox, which provide several methods of verification, Valve only accepts proof of credit card ownership. Debit cards and PayPal do not seem to be adequate, and having a previous, long-standing account does not relieve users of this requirement.

About half of the consumers in Australia do not possess a credit card.

ThunderSoft PC Optimizer v11.6 - Free lifetime license

Features​

Below is a comprehensive list of the key features that make the software a valuable addition to your needs:

  • System Clean– Cleans unnecessary files and optimizes storage to keep the system fast and organized.
    • System Junk Cleanup – Scans and removes temporary files, cache, logs, and leftover system data.
    • Large File Finder – Identifies oversized files that consume excessive disk space.
    • Duplicate File Cleaner – Detects and removes duplicate files to free up storage safely.
    • Disk Usage Analysis – Shows which file types and folders are using disk space.
    • Memory Optimization – Releases unused RAM to improve system responsiveness.
    • Disk Defragmentation – Reorganizes fragmented files to improve disk performance.
    • Software Manager – Manages and uninstalls installed programs completely.
    • Hardware Information – Displays detailed information about all system hardware components.
  • System Repair– Fixes system errors to improve stability and prevent crashes.
    • System Issue Detection – Scans the system for common Windows errors and misconfigurations.
    • DLL Error Repair – Fixes application errors caused by missing or damaged DLL files.
    • Game Error Fix – Resolves game startup failures and performance lag issues.
    • .NET Repair – Repairs .NET Runtime and Framework errors affecting software compatibility.
    • Registry Repair – Cleans and fixes invalid or broken registry entries.
    • Disk and File System Repair – Checks and repairs disk errors and corrupted system files.
    • System Image Repair – Restores damaged system image components.
    • System Restore Management – Creates and restores system restore points for recovery.
  • Compression– Reduces file size and manages compressed archives easily.
    • File Compression – Compresses files into 7z, ZIP, and TAR formats.
    • File Decompression – Extracts files from 7z, RAR, ZIP, TAR, and GZIP archives.
    • Batch Image Compression – Compresses multiple images at once without manual processing.
  • Data Recovery– Restores lost or deleted files from storage devices.
    • Deleted File Recovery – Recovers files accidentally deleted from the PC.
    • Lost File Recovery – Restores files lost due to system errors or disk issues.

Apple Key Note Topic

Yesterday was the release of the new iPhone 18 series and other Apple appliances . And boy did it become expensive.

What do you think of the " new" releases ?



ProductStarting Price (USD)Key Highlights
iPhone Duo$1,999Apple's first foldable phone; 7.6-inch inner display, 5.4-inch outer display, A20 Pro chip, titanium chassis, Split View on iOS.
iPhone 18 Pro$1,199$100 price increase; 2nm A20 Pro chip, 48MP main camera with variable aperture, vapor chamber cooling, smaller Dynamic Island.
iPhone 18 Pro Max$1,299Same Pro upgrades and variable aperture camera, paired with Apple's longest battery life yet (up to 45 hours playback).
Apple Watch Series 12$39942mm and 46mm sizes; 24-hour battery life, expanded workout tracking, new ceramic finish option, on-device Siri AI.
Apple Watch Ultra 4$799Up to 50 hours standard battery (84 hours in Low Power Mode), rugged titanium case, extended outdoor GPS tracking.
AirPods 5 (Standard)$129Open-ear design, Active Noise Cancellation, Adaptive Audio, and refreshed acoustic architecture.
AirPods 5 (Wireless Case)$149Adds wireless charging case, extended battery life, and stem volume touch controls.
Availability & Notes
  • The base iPhone 18 was absent from the showcase, moving to a staggered release window slated for spring.
  • Pre-orders for the iPhone 18 Pro series, Apple Watch models, and AirPods 5 begin immediately or on September 12, shipping on September 18.
  • The iPhone Duo ships later, with pre-orders beginning October 16 and deliveries starting October 23. Higher storage tiers scale up to $2,599 (1TB) and $3,199 (2TB).

The "Surprise and Shine" keynote held at Apple Park centered on major hardware transitions: Apple’s debut foldable, a shift toward 2nm silicon, camera hardware redesigns, and a staggered release calendar.

iPhone Duo

  • Form Factor & Display: Features an inward-folding, book-style design with a 7.6-inch inner OLED canvas and a 5.4-inch outer cover display. The hinge mechanism uses liquidmetal alloy components designed to minimize the display crease.
  • Biometrics & Chassis: Rather than internal Face ID sensors, authentication relies on a capacitive Touch ID sensor embedded directly into the side power button. The frame is built from Grade 5 titanium.
  • Cameras: Dual 48MP rear configuration (wide and ultra-wide). It omits a dedicated telephoto module to preserve internal volume and keep thickness down.
  • Software: Introduces foldable-specific additions to iOS, including dynamic Split View, app-pairing presets, and drag-and-drop multitasking across active panels.
iPhone 18 Pro & iPhone 18 Pro Max

  • A20 Pro Silicon: Built on TSMC's 2nm process node. It integrates a redesigned 6-core GPU, upgraded Neural Engine tailored for local Siri AI queries, and an internal vapor chamber to reduce thermal throttling during prolonged compute loads.
  • Variable Aperture Camera: The primary 48MP Fusion sensor now features a mechanical variable aperture ($f/1.4$ to $f/2.8$), allowing physical control over depth of field, optical bokeh, and low-light intake rather than relying purely on computational blur.
  • Aesthetics: A roughly 20% smaller Dynamic Island aperture alongside a new Burgundy colorway joining Black, Silver, and Glacier titanium.
Wearables & Audio

  • Apple Watch Series 12: Features upgraded PPG sensors with clinically validated continuous heart-rate tracking, an optional polished ceramic case option, and an S12 SiP designed to process Siri requests offline.
  • Apple Watch Ultra 4: Pushes standard multi-day runtimes to 50 hours, reaching up to 84 hours in Low Power Mode and up to 45 hours in continuous high-precision GPS tracking.
  • AirPods 5: Features a ground-up acoustic redesign in an open-ear footprint. The higher tier introduces Active Noise Cancellation and Transparency modes without requiring silicone ear tips.
Release Cadence

  • September 18, 2026: iPhone 18 Pro / Pro Max, Apple Watch Series 12, Apple Watch Ultra 4, and AirPods 5. Pre-orders open September 12.
  • October 23, 2026: iPhone Duo ships globally.
  • Spring 2027: Standard base-tier iPhone 18 line, as Apple officially bifurcated its smartphone release calendar.
Those prices o_O

is there a free backup or imaging software that will let me bootup from an external hard drive?

thanks in advance.

macrium reflect, aomi backupper, hasleo, ease us, clonezilla and others that i found are deceptive. they say free, but it is for just 1 month.

Windows update closes two zero-days used in active attacks

Microsoft’s September 2026 security update fixes 964 vulnerabilities, including two Windows zero-days already being exploited. Windows users and administrators should install the available updates and restart affected devices promptly.


Why these flaws matter​

Both zero-days are local elevation-of-privilege flaws. They could let an attacker or malware with limited access gain SYSTEM privileges, the highest level of control in Windows.

That added control can help an intruder disable defenses, reach protected information, remain on the device or spread through a network. The initial foothold would still need to come from another route, such as phishing or stolen credentials.

  • Microsoft lists 104 flaws as Critical and 860 as Important.
  • The wider release covers Windows and products including Exchange Server, SharePoint, SQL Server and Office.
  • High-severity remote-code-execution flaws were also fixed in Windows DNS Server and Remote Desktop Services.

What the attackers exploited​

One zero-day affects the Windows Update Stack. Microsoft says Windows can be made to access the wrong file by following a pointer without properly confirming where it leads.

The second affects Windows ALPC, an internal system that programs use to communicate on the same PC. Microsoft says code running inside a restricted AppContainer could exploit it to escape that sandbox and gain higher privileges without further user interaction.

Install and verify the update​

Open Settings from the Start menu, select Windows Update and choose Check for updates. Allow available updates to download and install, then restart when prompted.

  • After restarting, return to Windows Update and check once more.
  • Confirm that Windows reports “You’re up to date.”

Fake crypto exploit turns Chrome scripts into a wallet-address thief

Cisco Talos says a campaign is tricking cryptocurrency users into adding malicious JavaScript to Chrome under the promise of higher trading payouts. The code can replace legitimate deposit addresses with wallets controlled by the attackers.


Who the campaign targets​

The lure is a fake vulnerability report aimed mainly at people seeking to exploit cryptocurrency swap services for profit. Talos observed it being promoted through Telegram, DarkForums and text-sharing sites.

Earlier instructions told targets to paste a script into Chrome’s address bar. A newer version asks them to install Tampermonkey and add the script there, allowing it to run again whenever the targeted trading site is opened.

What the injected code changes​

The malicious script acts as a web skimmer, meaning it secretly changes payment information shown or handled by a website. It can intercept site responses, replace cryptocurrency deposit addresses and display a counterfeit bonus in the page.

  • Deposit addresses displayed in the trading interface can be changed to attacker-controlled wallets.
  • Copied wallet addresses can also be replaced through clipboard hijacking.
  • The Tampermonkey version reloads the code when the victim returns to the targeted site.

Google services used to deliver code​

Talos found that the loader retrieved obfuscated JavaScript from cells in a publicly published Google Sheets document through the Google Visualization API. Because the requests came from Chrome and went to Google-hosted services, they could resemble normal browser traffic.

This use of Google infrastructure does not mean Google Docs or Chrome are generally compromised. The attackers abused legitimate services after persuading users to install or execute their code.

Checks for potentially affected users​

  • Remove any Tampermonkey script added from an alleged crypto exploit guide, and review other user scripts before leaving the extension enabled.
  • Before sending cryptocurrency, compare the destination address with one obtained independently from the intended service; do not rely only on the page or clipboard.
  • If you used one of these scripts, review transaction records for unexpected recipient addresses. Talos linked 24 wallets that received about 0.159 BTC, worth roughly $10,000 at early-August 2026 values.
Do you allow user-script extensions such as Tampermonkey in your main browser, or keep them in a separate profile?

More than 100,000 fake stores are out to steal your card details

Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.

The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.

The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.

As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.

BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.

The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.

“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”
Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.

The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.

Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.

Windows 11 to share users’ ages with installed apps

Windows 11 is preparing to take on a job that apps and online services have largely handled until now, most of it badly: working out whether a user falls into the right age bracket.

Instead of asking people to type a birth date or tick an “I am 18+” box, Microsoft plans to let compatible apps request a broad age range and an age-verification status.

Age verification has long been left to self-reporting across much of the tech sector. It’s easy to see why that safeguard is weak: a kid can enter a false date and that’s all it takes.

Microsoft’s proposed approach aims to give apps a more useful answer without passing along a birthday.

Key takeaways​

  • Windows 11 age APIs are available to Windows Insiders, which means they will reach all Windows users soon
  • Apps can receive an age bracket and a verification status, not a user’s precise age or date of birth
  • The brackets are under 10, 10–12, 13–15, 16–17 and 18+
  • Apps need the appropriate account-information capability, and the user’s Windows privacy settings can deny access
  • The feature can support safer experiences for children, but it shouldn’t become a reason for apps to collect more data than they need...

Coolmuster Data Erasure 1.0.46 - 1 year for free

Protect your sensitive data from falling into the wrong hands with certified erasure protocols:

Drag-to-Destroy Simplicity: Easily erase files/folders by dragging them into the interface, ideal for quick cleanup of confidential documents, photos, metadata, or application traces.
Multi-Format Compatibility: Supports all file types, including business documents, personal media, and system files on Windows PC.
Zero Data Remanence: Advanced overwrite patterns ensure deleted files are permanently destroyed, preventing any chance of recovery.

Coolmuster PDF Password Remover - 1 year for free

Features:

  • This tool allows you to remove PDF passwords and restrictions with a right-click.
  • Batch decryption mode allows you to crack up to 200 PDF files simultaneously.
  • Right-click decryption: Right-click on any PDF file that you’ve imported into the program, and then remove it as you like.
  • You can reuse PDF after decryption.
  • It helps you get the job done in just a couple of minutes with its fast decryption speed and saves a lot of time.
Download:

Smart Game Booster - 6 months for free

Features
  • Auto boost FPS when you lauch the games
  • Real-time monitor FPS when you are in game
  • Real-time monitor hardware temperatures when you are in game
  • Record game moments easily
  • Unlock level 2 super boost for up to 50% faster game speed
  • Auto boost PC performance when launching games
  • Auto update drivers for smoother gaming experience
  • Auto defrag your hard disk for faster game loading speed
  • Keep your game safe from account stealing
Download:

ControlD free DNS issue

In Chrome for Windows, ControlD free DNS works as usual.

But in chrome for android, although it was working perfectly fine, lately it is not.

Websites show ads, and ControlD status check website shows it is off, although rechecking Chrome settings shows it is properly typed as it was in the first time!

Norton Safe Web Is Failing to Properly Identify Phishing and Fraudulent Websites.

It is extremely concerning and unacceptable for a well-known security product like Norton Safe Web to classify websites as “Safe” when those same websites are already identified as phishing or fraudulent by other security providers.The website in question is fraudulent, yet Norton’s product is telling consumers that it is safe to visit. This creates a serious security risk because users may reasonably trust Norton’s rating and proceed to a website that could potentially steal their personal information, credentials, or financial data.If Norton has not yet tested or determined the reputation of a website, it would be far more responsible to classify it as “Unknown,” “Not Tested,” or “Unrated” rather than incorrectly labeling it as “Safe.” There is a significant difference between not knowing whether a website is dangerous and confirming that a website is safe. Norton should not give consumers a false sense of security.

This is an issue that Norton needs to address, particularly if the Safe Web extension is not being maintained with the same level of attention and up-to-date threat intelligence that users expect from a major security company. If Norton cannot reliably maintain the extension and its threat feeds, continuing to present potentially fraudulent websites as “Safe” puts users at unnecessary risk.There was a time when Symantec operated Safe Web and its threat intelligence was more closely integrated with its security infrastructure. At that time, the service appeared to be much more effective at keeping website reputation information current and accurately identifying threats. Norton should seriously review how Safe Web determines website reputation, how frequently its threat intelligence is updated, and how it handles websites that have already been identified as malicious by other reputable security providers.

A security product should err on the side of protecting its users not reassuring them that a potentially fraudulent website is safe when it has not been adequately evaluated Thoughts on this?

Screenshot 2026-09-09 070516.pngScreenshot 2026-09-09 070550.png

Toy Ghouls deploys custom Windows backdoor against Russian organizations

Kaspersky says the financially motivated Toy Ghouls group has begun using a custom Windows backdoor in attacks on Russian organizations. A backdoor is malware that gives attackers remote access; in this case, it can collect system details, run commands and return the results.


A move toward custom attack tools​

According to Kaspersky researchers, Toy Ghouls has targeted Russian organizations since 2025. The group previously used public tools and leaked ransomware builders before moving to its own ransomware and, in July 2026, its first observed custom backdoor.

Kaspersky assesses that this move toward purpose-built tools may help the group make attacks more sophisticated and remain undetected for longer. That is an assessment rather than proof of the attackers’ intent.

What the backdoor can do​

After attackers have compromised a system, they deliver the backdoor through Windows Remote Management, a legitimate feature administrators use to manage Windows computers remotely. The malware can then install itself as a Windows service so it starts persistently.

  • Reports the computer’s public IP address, location and online status.
  • Sends operating details including CPU load, memory, disk use, uptime and hostname.
  • Receives commands, runs them through PowerShell or the Windows command line, and sends the output back.

Legitimate services used for control traffic​

Kaspersky identified two versions. One communicates through the public HiveMQ messaging broker, while the other uses an attacker-operated Element server based on the Matrix messaging system.

Use of a legitimate public service does not mean that service or its users are compromised. Defenders should instead investigate unexpected connections alongside unusual services, command execution and other signs listed in Kaspersky’s report.


Practical checks for defenders​

  • Review remote-management activity for unexpected file transfers to Windows systems, particularly where administrative access was not planned.
  • Look for unfamiliar Windows services associated with the filenames and service names in the vendor’s indicators.
  • Correlate unexpected messaging-service traffic with hidden PowerShell or command-line activity before deciding whether a host is infected.
Does your organization restrict Windows Remote Management to specific administrator accounts and network segments, or leave it available more broadly?

Fake CAPTCHA trick installs credential stealer through Windows WebDAV

A ClearFake campaign is using fake Google CAPTCHA prompts to trick Windows users into running commands that install the Amatera information stealer. Cisco Talos found related activity at a Ukrainian government organization, but assesses with moderate confidence that the operation broadly targets cryptocurrency and credentials rather than one organization.


What users should watch for​

The investigated chain likely starts on a compromised website. Malicious browser code displays a fake verification checkbox, then tells a Windows visitor to open Run, paste clipboard contents and press Enter.

That pasted command reaches a remote WebDAV location and launches a disguised DLL. WebDAV is a Windows-supported way to access remote files, but here it is abused to execute the attacker's loader.

  • Do not paste commands supplied by a CAPTCHA or other website verification prompt.
  • If you already followed such instructions, disconnect the PC from the network and run a full security scan.
  • From a separate trusted device, change exposed passwords and review cryptocurrency accounts and wallets for unexpected activity.

Credentials and wallet data at risk​

Talos found that one Amatera configuration covered browser data, messaging apps, more than 100 desktop wallet locations, password managers, authenticators, email and FTP clients, VPN software, and remote-access tools.

The malware also searched common user folders for private keys, wallet backups, authentication data, password databases and certificate files. Talos said most collection rules focused on cryptocurrency information and credentials.

Different follow-on threats​

The two observed Amatera builds received different follow-on tasks from their command-and-control servers. One branch installed cryptocurrency-stealing and proxy capabilities, while the branch seen at the Ukrainian organization attempted to install an unauthorized NetSupport Manager remote-access tool.

NetSupport Manager is legitimate administration software, but an unauthorized installation can give an attacker remote access. Talos assessed with moderate confidence that the branch using it was operated by a Russian threat actor, based on configuration pointing to a server at a Russia-based IP address.

Have you encountered a website verification prompt that asked you to paste a command into Windows Run or Terminal?

Infostealers are adding AI-agent data to their target lists. GenD research found Remus, Amatera and CallbackBeaver collecting data associated with it.

Our analysis of recent information-stealer collection rules found a much newer category alongside the familiar browser, wallet, and credential targets: local data associated with Claude, Cline, Codex, Continue, Cursor, OpenCode, and other AI-assisted development tools.

This was not an isolated experiment: over a three-month period, our Windows telemetry recorded Amatera and Remus detections among tens of thousands of protected users. Amatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode. The figures may overlap and describe detections rather than successful infections, but they show that AI agent data has already entered the information-stealer economy.

What the malware is collecting goes far beyond harmless preferences. Depending on the agent and its configuration, local files may contain access and refresh tokens, credentials stored in MCP configurations, prompt histories, conversation databases, account details, and traces of the projects a developer has been working on. In one archive, an attacker may obtain both the means to access an account and the context needed to understand what is valuable behind it.


Our findings focus primarily on locally installed coding agents and agentic developer tools, and they do not point to a new way of compromising the device or to a vulnerability in an AI model or agent. The information stealer is already running; what has changed is the concentration of valuable information in predictable locations, sometimes in plaintext, and the ease with which those locations can be added to an existing collection list.

TuxTalk - Ubuntu 26.04.1 LTS

There is something uniquely satisfying about running Fedora on a daily driver. For days it was brilliant—cutting-edge kernel improvements, polished modern desktop performance, and rapid access to upstream features that made the entire workflow feel sharp and responsive.

Then came a routine package update.

Following what appeared to be a standard system refresh, a sudden crash disrupted the session. Upon rebooting, the environment became erratic: graphical sessions hesitated to launch cleanly, display server hooks misbehaved, and core system daemons produced intermittent failures during boot. While an uncooperative system can usually be pinned down with persistent log analysis, chroot rescues, and rolling back upstream packages, a primary workstation has a single non-negotiable requirement: immediate, predictable reliability.

When uptime directly dictates productivity, there is little room for indefinite troubleshooting.

The pragmatic choice was to return to a rock-solid foundation: Ubuntu 26.04.1 LTS. While leading-edge distributions deliver the thrill of modern Linux development, LTS releases exist precisely for moments like this. The reinstallation was smooth, the core configuration took only minutes to reapply, and the system instantly returned to a calm, battle-tested baseline.

Fedora remains an exceptional distribution for seeing where the Linux ecosystem is heading tomorrow. But for getting critical work done today without unexpected surprises, returning to Ubuntu LTS is a reminder that stability is often the ultimate feature.

1788898094355.png

Microsoft Promises Faster Edge Extension Approvals

Microsoft is speeding up the review process for Microsoft Edge extensions while also highlighting the highest-quality extensions on its Edge Add-ons website.

“Rapid adoption of AI-assisted coding is enabling developers to build extensions faster than ever,” the Microsoft Edge team explains. “More developers are building, iterating, and submitting extensions, which is great for the ecosystem and ultimately gives users more choice. [But] it also creates a challenge: How do we keep up with the pace at which the ecosystem is growing, while maintaining a high bar for quality?”

Microsoft added an expedited review process for browser extensions a year ago, but submission volumes have only increased since then, and that’s led to longer turnaround times. To combat this, it is automating many of the repeatable validation checks in its extension review process and streamlining the entire process.

It’s also introducing a new Featured badge on the Edge Add-ons website to highlight extensions known to have good quality, reliability, security, and user experiences. To get the badge, extension makers need to adhere to Microsoft’s best practices for extensions. And because extensions can change frequently, Microsoft will refresh its Featured badges every 15 days.

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.

The approximate number of bugs in each vulnerability category is listed below:
  • 438 Elevation of Privilege Vulnerabilities
  • 19 Security Feature Bypass Vulnerabilities
  • 258 Remote Code Execution Vulnerabilities
  • 173 Information Disclosure Vulnerabilities
  • 56 Denial of Service Vulnerabilities
  • 16 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count vulnerabilities released by Microsoft on Patch Tuesday itself.

Therefore, today's total does not include 204 flaws fixed earlier this month, including vulnerabilities in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge (Chromium-based), Microsoft Fabric, and Power Automate.

Windows 10 September 2026 Patch Tuesday (KB5122878)

It's the second Tuesday of the month, which means we're getting a new set of Patch Tuesday updates for Windows 10. Microsoft is rolling out the monthly security update (also called "B release") for Windows 10 users in the the Extended Security Updates (ESU) program.

The new updates are being distributed under KB5122878 for Windows 10 22H2, 22H1 and bumps the build numbers to 19045.7725 and 19044.7725. You can download the new update directly from the Microsoft Update Catalog at this link.

Here's the complete changelog of the KB5122878 update for Windows 10:
  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
  • [Date and Time] This update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026. This change ensures that the correct local time is displayed after the transition.
  • [OMA DM protocol] This update improves the logging features of the OMA DM Client (omadmclient.exe) component. More debug information is now saved when connecting to a server.
  • [Windows Code Integrity policies] Improves application compatibility during Windows certificate-authority rotation by recognizing Microsoft Windows Production PCA 2026 RSA2048-SHA256 as equivalent to PCA 2011.
  • [Remote Desktop] This update addresses an issue that affects Remote Desktop audio redirection. Audio from the remote session might not play on the local computer in certain configurations.
  • [BitLocker Group Policy] This update addresses the "Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key" known issue.

Windows 11 September 2026 Patch Tuesday (KB5124008, KB5122880)

Microsoft has released the September 2026 Patch Tuesday updates for Windows 11 25H2, 24H2. The 25H2 and 24H2 update is provided via KB5124008 (manual download link below), build 26100.9445 on 24H2, and build 26200.9445 on 25H2, after applying the updates. Windows 11 23H2 is available under KB5122880 (manual download link below), build 22631.7582.

The changelog for Windows 11 25H2, 24H2 is given below:
  • [Security updates] This update provides security improvements.
  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
  • [Mouse] Fixed: This update addresses an issue that prevented customized mouse cursor settings, including pointer style and color, from displaying correctly. Selected cursor options and colors now work as expected.
  • [Personalization] Fixed: This update addresses an issue where desktop background and other personalization settings might not load correctly, causing the desktop background to appear black.
  • [Teams and Outlook on Arm64 PCs] Fixed: This update addresses an issue that could cause Microsoft Teams and Microsoft Outlook to unexpectedly close on Arm64-based PCs.
  • [Date and Time] This update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026. This change ensures that the correct local time is displayed after the transition.
  • [Remote Desktop Audio Redirection] This update addresses an issue affecting Remote Desktop audio redirection that could prevent audio from a remote session from playing on the local device in certain configurations.
  • [OMA-DM Client Logging] This update improves diagnostic logging for the OMA-DM client, providing additional information to help troubleshoot device management server connection issues.

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia.

Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well.

In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31.

Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection.

The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton.

“Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected,” a GenDigital spokesperson said, responding to a SecurityWeek inquiry.
FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, the researcher says.

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal,” CrowdStrike told SecurityWeek.

The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components.

“While this bug does not get SYSTEM privileges immediately, it can be used cross user to user boundary easily or even compromise the dwm.exe process. I didn’t look deeply into it, but I’d be happy to see someone making a full exploit out of it,” Nightmare Eclipse notes.

“We are aware of reports describing a proof-of-concept that demonstrates improper access controls on a shared memory section used by certain NVIDIA GPU display driver components on Windows. NVIDIA is reviewing the reported behavior through our established security and product engineering processes. NVIDIA takes reports of this nature seriously and is actively investigating to determine the root cause, affected configurations, and appropriate remediation,” an Nvidia spokesperson said.

Security researcher Kevin Beaumont said late last week that the Avast, CrowdStrike, and Kaspersky exploits work.

Hackers Stream Real Google Login Pages to Steal Passwords and 2FA Codes

NordVPN researchers found a phishing service relaying live Google sign-in sessions to intercept passwords, 2FA codes, and active authenticated account sessions.
Cybersecurity researchers from NordVPN have identified a phishing platform that uses a live Google login session to steal passwords and two-factor authentication codes from victims.

The campaign starts with an email designed to look like a Google Voice voicemail alert. The messages are sent from compromised legitimate accounts, which can help them pass standard email authentication checks.

NordVPN’s threat intelligence unit first identified executives/CEOs as the key targets, but the team later found that phishing emails were not limited to them and employees at other organizations were targeted as well.

Attackers Relay Real Google Login Pages
Read more: https://hackread.com/hackers-google-login-pages-steal-passwords-2fa-codes/

LG TV flaws could let attackers listen in, even in standby mode

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR).

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe​

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.
Our earlier guide to disabling ACR includes instructions for several popular TV brands.

ImageUpscale AI Pro v1.0 - Free lifetime license

Features​

  • Intelligent Neural Upscaling: Uses trained AI models to reconstruct realistic detail rather than simply stretching pixels.
    • Fast Model: Prioritizes processing speed for quick turnarounds on large batches.
    • High-Quality Model: Focuses on pixel-perfect detail for images where precision matters most.
    • Balanced Model: Offers a middle ground between speed and output quality for everyday use.
    • Multi-Scale Model: Handles images with varying levels of detail across a single frame.
  • Massive 8x Scaling: Enlarges images by 2x, 3x, 4x, or 8x while reconstructing fine textures instead of just enlarging existing pixels.
    • Texture Reconstruction: Rebuilds realistic surface detail lost in low-resolution originals.
    • Detail Preservation: Maintains natural appearance even at the largest scale factors.
  • Efficient Batch Processing: Processes multiple images in a single operation to save time on large projects.
    • Multi-Format Support: Handles JPG, JPEG, PNG, BMP, TIFF, and WEBP files within the same batch.
    • Lossless Quality Output: Preserves original image integrity throughout the enhancement process.
  • Real-Time Comparison Viewer: Displays before-and-after results side by side for immediate quality assessment.
    • Zoom Capability: Allows close inspection of fine detail differences between original and upscaled versions.
  • Functionality-First Interface: A clean, distraction-free design built around performance rather than decorative elements.
    • One-Click Processing: Starts image enhancement quickly without navigating complicated menus.
    • Drag-and-Drop Support: Simplifies loading images into the processing queue.
  • Smart File Management: Automatically names and organizes output files to prevent confusion between originals and upscaled versions.
    • Customizable Output Settings: Lets users choose destination folders and naming conventions.
  • Progress Monitoring: Tracks processing status in real time so users know exactly how far along a batch job is.
    • Time Estimates: Provides an approximate completion time for ongoing tasks.
  • Local & Private Processing: Keeps all AI computation on the user’s own machine rather than sending data to external servers.
    • Total Data Security: Ensures sensitive or personal images are never exposed to third parties.
  • Resource-Efficient Engine: Built on a C++/C# foundation optimized for modern multi-core processors.
    • CPU Acceleration: Speeds up processing without requiring a dedicated graphics card.
    • Efficient Memory Management: Handles large image files without excessive strain on system resources.

Ashampoo Snap 17 for free

Features​

  • Capture and edit any screen content
  • Flexibility and precision for your captures
  • All the information you need in a single image
  • Create your own real-time videos
  • Works with any display
  • Perfect for web content
  • Video editing for the perfect movie
  • Safely send or upload to the cloud
Download:

AnyHeic - Heic Photo Converter for Win v1.0.17

AnyHEIC is designed for simple and efficient image conversion. Add multiple HEIC or HEIF files, choose your preferred output format, adjust the image settings, and convert them all in one batch.

All image processing is completed locally on your computer. Your photos are never uploaded to a server or cloud service, helping you keep personal images and metadata private.

CONVERT HEIC AND HEIF IMAGES
  • Convert HEIC and HEIF files into widely supported image formats:
  • - HEIC to JPG
  • - HEIC to PNG
  • - HEIC to WebP
  • - HEIF to JPG
  • - HEIF to PNG
  • - HEIF to WebP
JPG is ideal for photos and broad compatibility, PNG is suitable when you need high-quality image output, and WebP can help reduce file size while maintaining good visual quality.

Coolmuster Android Backup Manager - 1 Year free

Features

  • Back-Up Android Phone in 1 Click
  • Customize the storage location of backup files
  • Various file types are supported:
    • Contacts,
    • messages,
    • call logs,
    • photos,
    • music,
    • videos,
    • documents
    • user apps.
  • Restore Android from Backup in 1 Click
  • Quickly scan out and list all the backup files you’ve made on your computer
  • Restore any listed backup file and any target file types into any connected Android device.
  • Add new backup folders manually from the computer for restoration
  • 2 Device Connection Methods: USB and Wi-Fi
  • High Compatibility, Fast Transfer, Read Only, etc.
  • lmost all Android phones and tablets in different phone brands and models are supported
Download:

A Clanker Pitted Fedora Against Windows 11. Fedora Won, Mostly

PhoneBuff is a company that built its name by offering lab-tested, standardized reviews for smartphones run by robotic hands. Their YouTube channel showcases a range of assessments that cover speed tests, drop tests, and battery tests.

When viewers started poking them about trying Linux after a recent performance comparison they did between a Dell XPS 13 and MacBook Neo, they responded.

Taking two identical Dell XPS 13s with an Intel Core 5 320 and 8GB of RAM, one on Windows 11 and one on Fedora, the PhoneBuff crew ran the same real-world apps and workflows on each, timed by their robot mouse and keyboard (aka the clanker in question).

By the time testing concluded, Fedora won six of eleven timed tests while four tied, and Windows 11 took home a single win.

A new mpv-based media player

SayOnce Voice Dictation Software v1.2 - Free lifetime license

Features​

  • Global Hotkey Dictation:Hold a system-wide hotkey, speak, and release to paste recognized text directly at the cursor in the active window.
    • Default Ctrl + Win Binding: The push-to-talk combination is set out of the box but can be reassigned to any preferred key combination.
    • Configurable Injection Methods: Multiple text-injection approaches are available to keep compatibility high across different Windows applications.
  • Offline Speech Recognition Engine:All voice processing happens locally on the PC using a downloaded recognition model, so no audio is uploaded anywhere.
    • One-Time Model Download: A roughly 500 MB download installs the recognizer once, after which the software runs without internet access.
    • No Cloud Dependency: Dictation and transcription both continue to function during outages or on networks without internet.
  • Dictation Widget Overlay:A small on-screen widget appears at the bottom of the display while dictating, showing live recognition status.
    • Visual Feedback: Users can confirm the hotkey is active and speech is being captured before releasing the keys.
  • Prose, Code, and Email Presets:Switch between formatting modes depending on the type of content being dictated.
    • Prose Mode: Applies natural punctuation and paragraph breaks suited for letters, articles, and general writing.
    • Code Mode: Avoids automatic formatting and auto-correction behavior that would otherwise break dictated source code or command syntax.
    • Email Mode: Tunes punctuation and sentence structure for the shorter, conversational tone typical of email correspondence.
  • Personal Dictionary and Snippets:Store frequently used terms, product names, and phrases so the recognizer applies them correctly every time.
    • Custom Vocabulary Entries: Add technical terms or brand names that generic recognition engines commonly misinterpret.
    • Text Expansion Snippets: Say a short phrase such as “my address” and have it automatically expanded into a longer stored block of text.
  • Batch Audio and Video Transcription:Convert entire recordings into text files using the Files tab instead of transcribing manually by listening.
    • Drag-and-Drop File Loading: Add MP3, MP4, WAV, M4A, FLAC, OGG, MOV, and MKV files by dragging them into the application window.
    • Unlimited Daily Processing: There are no daily word caps or per-minute charges once the file transcription runs on your own PC.
    • Clipboard and Output Folder Access: Extracted text can be copied directly to the clipboard or retrieved as a saved file from the output folder.
  • Multi-Language Support:Dictate and transcribe in a wide range of spoken languages while using the interface in your preferred language.
    • 25+ Default Speech Languages: A broad set of speech recognition languages is included from installation.
    • 100+ Downloadable Languages: An alternative model expands language coverage well beyond the default set.
    • 20+ Interface Languages: The application menus and settings can be displayed in more than 20 languages.

SHARPEN Projects Professional 3 for free

Features & Capabilities:

  • Adaptive Sharpening: Uses methods like “Adaptive Multi-scale Deconvolution” to look at pixels and apply sharpness in a smart way, looking at nearby pixels to see how clear they are.
  • Motion Blur Correction: Fixes motion blur in action images (sports, animals) by adjusting the camera’s focus and exposure.
  • Intelligent Masking: This is a new feature in version 3 that lets you sharpen only certain areas (like skin, the sky, or details) without changing others. It keeps tones and edges safe.
  • RAW Module: Works with a wide variety of RAW file types, allowing for lossless adjustments, including exposure, noise, and color correction.
  • Selective Processing: Use effects based on the type of image (portrait, landscape, or movement) and use brushes that you may change to make exact changes in certain areas.
  • Oversampling Mode: Gives you a more precise sharpness computation.
  • Blur Function and Comparison View: These features help you see how sharpening affects an image by blurring it and showing it next to another image.
  • Batch Processing and Metadata: Change the metadata of an image and process more than one photo at a time.
Download:

FRANZIS CutOut 10 Professional for Free

FRANZIS CutOut 10 Pro Features:

  • Directly swapping background layers is now easy!
  • Segmented micro-cut edge recognition for white background.
  • Chroma Key matting–Blue screen technology.
  • Inner/outer edge matting.
  • Tools for improving masks.
  • Contour tool for precise, quick selection.
  • Selectable user interface light/dark.
  • Custom icon sizes, 4K compatibility.
  • Ready for any task with three finely tuned matting methods.
  • Cut out hair, fur, and other delicate objects in just a few clicks.
  • Comes with an integrated RAW developer.
  • The combination of color, edges, and segment recognition results in significant time savings.
  • Chroma key matting for Hollywood-like blue screen effects.
  • Remove unwanted objects from your images at the click of a button.

Download : https://transfer.franzis.de/supportdownload/70806-9_CutOut-10_professional_winde.zip

Franzis Photo-Video Toolbox (6 Photo & Video Tools) for free

Foto - Video Bundle with :

  • Zoom #1 — enlarges a photo way past its native size while keeping edges crisp. Handy when you want to blow up a shot to poster or banner scale without it turning into mush.
  • SHARPEN Video #1 — pulls detail back into soft or older clips, so footage from a dated phone or action cam suddenly looks a class above.
  • LUT #1 — lifts a colour look from one image and drops it onto another in a couple of clicks. You can also bake your own filters and batch them across a folder.
  • LUT Video #1 — the same colour-grading idea, but for video. Raw clips go in, styled footage comes out.
  • DIVE #1 — built specifically for underwater photos, with nine presets and water-depth settings to fix that murky blue-green cast.
  • DIVE Video #1 — does the same rescue job for underwater video, using the same specialised engine.
Download:

Sticky Password Premium V8.9 - 1 Year for free

Features of Sticky Password Premium 8:



  • Password Manager – Password-safe – organize and securely store your passwords in whatever way works best for you. A password generator generates a new password automatically whenever you need a new password.
  • Autofill – Automatically fills your logins and passwords to appropriate fields on a given URL and even in Windows applications. One-click logs you into any of your favorite sites and applications.
  • Form Filling – Automatic form filler completes even the longest forms for you. No need to register every time you shop or download – once you’ve stored your information in the password manager, you can recall it instantly on any device whenever you need it
  • Biometrics – Fingerprint scanning – identity verification of the account holder can be made with just one swipe of a finger.
  • Super Secured Data – AES-256 encryption – the world’s leading standard also used by the military. And your master password is not known to anyone else but you – not even to us.
  • Two-Factor Authentication – You have the option of unlocking Sticky Password using your Master Password and a unique time-based code generated every 30 seconds on your smartphone.
  • All Major Platforms – Sticky Password works across all 4 major platforms – on your PC, Mac, tablet, and smartphone. Windows, Mac OS X, Android, and iOS operating systems are supported.
  • Cloud Sync Across Devices – Synchronization via our cloud servers – only if you want. The synchronization can be made over local Wi-Fi or manually so that your encrypted data never leaves your devices.
  • Cloud Backup – There’s an encrypted password database backup available for you in the cloud in case you lose your device or data stored on it – only if you want.
  • Local Wi-Fi Sync Across Devices – You don’t have to synchronize only via our cloud servers. The synchronization can be made over local Wi-Fi or even manually so that your encrypted data never leaves your devices.
  • Priority Support – Access to the support team for all their questions. Contact us at support@stickypassword.com using the email address associated with your Premium account.
  • Saving Endangered Manatees – With each Premium version sold we support manatees around the world.

MalwareTips AI

Deployment test of the new MalwareTips AI
This discussion checks public forum replies and will remain open for community feedback. The scenario below is hypothetical.

Microsoft Defender SmartScreen blocked a download in Edge. I cancelled the download and did not open or run the file. Does the warning alone mean the computer is infected? Please check the relevant official Microsoft guidance, explain what the warning does and does not tell us, and give proportionate next steps.

Download Sentinel Reviews

Download Sentinel is an extension available for Chromium-based browsers (Brave, Google Chrome, Edge, Vivaldi, etc.) by @LinuxFan58
Its purpose is simple: to check what you’re downloading via VirusTotal and protect you from potentially malicious downloads.
To do this, you need to obtain a (free) API key and register on the VirusTotal website.

Sentinel also features a site reputation check via the Quad9 service.

Let’s take a look at how it works...



As shown in the test, Download Sentinel flags all downloads as malicious, earning a score of 10/10.

However, it is not a web filter! During my anti-phishing tests on fake online stores, Sentinel didn’t block any of them despite having a reputation check—which is normal, since that’s not its purpose… (though I’d love to see that feature added someday).
Recommended as a supplement to your antivirus software, but it doesn’t replace it.

Possible License Key Issues Affecting AVG and Gen Digital Products

It appears that AVG, or possibly Gen Digital, may currently be experiencing issues with its license key activation service and its ability to recognize or accept valid license keys. I recently performed a clean installation of my system, which required me to re-enter my AVG product license key. However, I noticed that the system initially did not recognize or accept my license key, even though the key was valid. I waited approximately 20–30 minutes and then tried entering the license key again. This time, the key was accepted without any problems, and the product activated normally.

I’m not sure whether this is an isolated issue or if it is affecting other Gen Digital products and customers as well. Given that the license key worked after waiting and trying again later, it may have been a temporary issue with the activation or license verification service. I have contacted support to report the issue and make them aware of what happened. Hopefully, they can determine whether there is a larger problem with the license activation system. I copied and pasted my license key directly, so I know it was entered correctly and that the issue was not caused by a typing error or user error. Initially, the system would not recognize or accept the key. After waiting approximately 20–30 minutes and trying again, the exact same key was accepted without any problems.

Brave Ad-Shields - How many filter lists have you subscribed to?

This poll is open to all forum members who use the Brave browser.
Specifically, it is intended for those who use Brave Ad-Shields, even if only occasionally.

I'd like to remind forum members that before voting, they must enable this flag in Brave:

  • Show hidden adblock filter list components
Reveals adblock filter list components in brave://settings/shields/filters that would normally be hidden.

The enabled filter lists are here:

Code:
brave://settings/shields/filters


Otherwise, the count of enabled filter lists is certainly lower than the actual number you have.;)


Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended

Identified vulnerabilities​

In the course of our research we identified six vulnerabilities in RouterOS; below we describe the three most important ones, and all of them can be found on a dedicated page.

CVE-2026-67276 - SSH authentication bypass (CVSS: 9.2)​

RouterOS did not properly verify public keys used for SSH authentication - in particular, it did not compare the entire RSA public key assigned to a user. An attacker who knew the username and the public modulus of the user's key could craft a different key and log in via SSH without possessing the corresponding private key. The privileges obtained were equivalent to those of the targeted account.

CVE-2026-86060 - SSH session privilege manipulation via a crafted username (CVSS: 9.2)​

RouterOS did not properly handle usernames beginning with a disallowed character in the SSH login mechanism. By using a crafted username, an attacker could elevate their privileges. The resulting session had full administrative privileges in the RouterOS system.

CVE-2026-67277 - memory disclosure and crash via bandwidth-test (CVSS: 8.8)​

The bandwidth-test service allowed an unauthenticated connection to enter a state that should only be reachable after logging in. Combined with two separate flaws - disclosure of uninitialized data from the packet buffer and an integer underflow in size validation - this enabled kernel memory leakage or a remote DoS attack leading to a system restart.

Recommendations​

We recommend updating RouterOS immediately to one of the versions containing the fixes: 7.25beta3, 7.24.2, 7.23.4, or 6.49.21. After updating, check the logs for the device compromise message and the value of the flagged marker in the output of the /system/device-mode/print command. Also verify the configuration for unknown users, scripts, and other unrecognized changes. The inspection and further steps should follow MikroTik's security bulletin and the Flagged documentation referenced therein. The absence of the marker does not rule out an earlier compromise.

If the patch cannot be installed immediately, do the following until the update is applied:

  • Disable the exposed services or block access to them from all addresses outside trusted management networks. This applies in particular to SSH, WWW/WWW-SSL, and the bandwidth-test server;
  • Do not initiate TLS connections from an unpatched device or use the built-in SSH clients (/system ssh and /system ssh-exec), especially when communication passes through untrusted networks or is directed at untrusted hosts.

What was actually fixed in the new update?

The affected versions are:​

RouterOS 7.24 / 7.24.1 → fixed in 7.24.2
RouterOS 7.0–7.23.3 → fixed in 7.23.4
RouterOS 6.x → fixed in 6.49.21

Switzerland's Federal Government is Replacing Microsoft on 3,000 Computers

Switzerland's federal government has launched a pilot program to replace Microsoft 365 with open source alternatives across 3,000 workstations. That's about 7% of the federal workforce. The target is to complete the migration by end of 2027.

This move follows a successful proof-of-concept and a new digital sovereignty law. A separate fast-track military migration is also already underway.
According to Matthias Stürmer, professor at the Bern University of Applied Sciences (BFH), Microsoft’s supremacy in public institutions poses three problems that are driving this migration.

First is the risk of foreign access. US cloud legislation could expose Swiss government data to foreign authorities.

Second is the risk to service continuity, as dependency on a single foreign vendor creates operational risk.

The third risk is the escalating costs as proprietary licensing fees are rising with no Swiss leverage.
Switzerland's military cybersecurity unit, Cyber Command, is not waiting for the civilian pilot. It is already poised to replace Microsoft 365 entirely with openDesk by October 2026.

It is pretty much the same reason. Military doesn't want foreign governments accessing sensitive Swiss data.

Sandboxie-Plus v1.18.4 / 5.73.4 Latest

Release v1.18.4 / 5.73.4 Latest
This release focuses primarily on refinements to SandMan’s INI editor, shell notification handling, and several smaller reliability fixes.

The SandMan INI editor has received a substantial auto-completion overhaul. Completion candidates are now ranked using context-aware semantic matching and fuzzy matching, while metadata is synchronized independently for each editor instance. Refreshes are also deferred during rapid typing or deletion to reduce unnecessary updates and improve responsiveness.

The completion popup itself has also been refined. Candidate tooltips no longer retain stale information while editing, Template and TemplateReject entries now show only the relevant setting-name information, and large description tooltips have been adjusted to avoid jumping unnecessarily between sides or obscuring completion candidates.

Shell notification handling has also been updated. UseShellNotifyIconProxy remains enabled by default when OpenWinClass=* is configured, preserving the behavior required by these sandboxes, while other sandboxed processes now use direct routing by default unless proxying is explicitly enabled. To make troubleshooting this behavior easier, low-noise SbieTrace logging has been added for Shell_NotifyIconW calls. The trace records the notification message, icon identity using either NIF_GUID/GUID or HWND/uID, and whether the effective route was direct or through the proxy.

A problem with shortcuts created from SandMan’s File Panel has been fixed. Previously, the “Create Shortcut” action did not set a working directory, causing sandboxed applications to inherit SandMan’s current directory. Programs relying on relative paths could consequently fail to locate their data files. Shortcuts created through the File Panel now receive the appropriate working directory.

This release additionally fixes an incorrect return type in SbieSvc and corrects archive path cleaning behavior.

Sandboxie Plus 1.18.4 is primarily a maintenance and usability release, with the most visible improvements affecting INI editing and completion behavior while also tightening shell notification routing and addressing several smaller issues reported since the previous release.

For a full list of changes please review the change log.

You can support the project through donations, any help will be greatly appreciated.
If you have issues with an update installation, just uninstall the previous version keeping the sandboxie.ini and reinstall the new build.

https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.18.4
https://forum.xanasoft.com/threads/sandboxie-plus-v1-18-4.13130/
https://www.wilderssecurity.com/threads/sandboxie-plus-v1-18-4.460665/
https://www.patreon.com/DavidXanatos/posts/sandboxie-plus-4-168782469

Best new and upcoming Windows 11 25H2 and 26H2 features

Microsoft's messy update schedule makes it hard to track all the new features in Windows 11. We tried gathering the best ones in one place.
Windows 11, and by extension Microsoft, has had a turbulent couple of years. From frequent issues caused by updates to going overboard with AI everywhere, it’s reasonable to say users haven’t exactly been satisfied with the state of Windows 11. That resulted in plenty of negative feedback, with people urging Microsoft to focus on fixing and improving its operating system. And lately, it looks like the company has been listening.

Microsoft has unveiled all sorts of new features and changes over the past few months. Most of them aren’t monumental, but they tackle particular issues users have had with Windows 11 lately. Taken together, they should make the operating system noticeably better, so there’s quite a bit to look forward to over the coming months.

Before we start talking about the best new Windows 11 features, there’s one important distinction. Microsoft’s schedule for delivering new Windows features is a little messy these days. Some of the changes on this list have already started rolling out to regular Windows 11 users, while others are still limited to Insider builds.
Read more:

This Facebook, Instagram, TikTok free streaming app ad leads to "full device takeover"

Social media ads disguised as free streaming services spread StreamRat, enabling attackers to remotely control Android devices.
Cybercriminals are increasingly turning to social media advertising to distribute malware, and a new Android banking trojan shows just how dangerous these campaigns can become. Security researchers have uncovered StreamRat, a previously unknown piece of Android malware that was promoted through Meta and TikTok ads disguised as a free TV streaming service.

According to ThreatFabric, which uncovered the campaign, these malicious ads primarily targeted users in Spain, with one Meta advertising campaign reaching approximately 570,000 users between June 11 and July 3, 2026. The researchers discovered the campaign while monitoring streaming-themed lures and found that victims were eventually directed toward a malicious APK capable of giving attackers extensive control over an infected Android device.

The attack begins with adverts promoting what appears to be a free streaming service. Once a user clicks that ad, they are taken to a specially designed website that checks whether the visitor is using Android. Users on other operating systems are simply shown an error, while Android users are presented with a download option.

The website then determines whether the victim opened it through Facebook, Instagram, TikTok, or a regular browser and displays instructions accordingly. These instructions misleadingly convince the victim to allow installations from unknown sources and grant the malware access to Android's Accessibility Services.

The downloaded APK acts as a dropper to help deliver than the final malware. It can even ask the victim to make it the device's default launcher, meaning pressing the Home button sends the user back to its interface. The dropper then downloads the actual StreamRat payload, installs it and launches it before eventually removing itself as the default launcher.

An interesting part of the infection chain is that the dropper creates a deliberate, non-functional VPN connection. If you are wondering why, this is done to effectively cut other apps off from the internet while the dropper itself can continue operating. ThreatFabric believes this is designed to make it harder for security products to perform cloud-based checks on the newly installed malware. Google Play Protect could be one of those, although the researchers point out that the technique does not completely bypass Play Protect because it also has offline detection capabilities.

Once StreamRat is running and has obtained Accessibility Services access, things get considerably more serious. The malware connects to its command-and-control (C2) server, collects information about installed applications and continuously monitors what is displayed on the screen. It can also capture data entered by the victim.

The trojan supports two different forms of remote screen access. Its VNC ( (Virtual Network Computing) mode uses Android's MediaProjection API to capture the screen, while its hidden VNC (HVNC) mode uses the Accessibility API to take screenshots without displaying the usual screen-sharing indicator. The latter can capture a screenshot every 200 milliseconds, giving an attacker a near-real-time view of the device without the victim even suspecting anything.

StreamRat can go even further with its Accessibility Node Viewer. ThreatFabric describes this as a text-based form of screen casting, where the malware reconstructs what is displayed using individual AccessibilityNodeInfo elements instead of sending a bitmap of the screen. The firm remarks it's "one of the fastest ways to collect, transmit, and visualize what is currently displayed on the victim’s device."

The malware also supports overlay attacks, which could be greatly useful for stealing banking credentials. StreamRat can display fake interfaces over legitimate applications, allowing an attacker to create convincing prompts and capture information entered by the victim. It also has several overlays designed to distract the user while the attacker controls the device in the background.

For example, the malware can cover around 98% of the screen with a black overlay that blocks the victim's touches while the operator continues interacting with the device. It can also display a fake Android update screen or a custom HTML-based screen. There's a lot more in the investigation which you can read in full here on ThreatFabric's website.

Essentially, the StreamRat campaign really highlights why installing an APK from random sources can be so risky. It also shows why Google heavily discourages side-loading of apps on Android.

OpenAI and Microsoft for copyright infringement

The Seattle Times and Newsday accused the two AI giants of using their content without permission.
The Seattle Times and Newsday have jointly filed a lawsuit against OpenAI and Microsoft, accusing the companies of training their AI models using copyrighted works. The two news organizations who filed the legal action on Friday called generative AI "a snake eating its own tail" that would destroy the news organizations and content that it trained on.

In the lawsuit, Seattle Times and Newsday alleged that OpenAI and Microsoft were "methodically scraping" news articles in a way that bypasses paywalls. The news organizations claimed that this method of training AI models has harmed their business models, giving users an AI-generated alternative to news articles and reducing the traffic and digital advertising revenue for Seattle Times and Newsday. The lawsuit also alleged that these AI models would create hallucinations attributing false information to the news outlets and remove copyright management information on articles.

Seattle Times and Newsday join a growing list of news organizations that have started a legal battle against AI companies. In 2023, the New York Times set the precedent by filing a lawsuit against OpenAI and Microsoft for similar reasons. The trend has continued, with CNN suing Perplexity for copyright infringement earlier this year. However, other news organizations like AP and Vox Media have taken a different route and partnered with OpenAI, allowing the AI giant to train models on their material.


Read More: Two more news organizations sue OpenAI and Microsoft for copyright infringement - Engadget

AnyMP4 Video Repair - 1 year for free

Features of AnyMP4 Video Repair:

  • Versatile Video Format Repair: Supports a wide range of video formats including MP4, MOV, and 3GP for comprehensive repair action.
  • Cross-device Compatibility: Promises seamless video repair across different devices such as cameras, phones and other Internet-sourced videos.
  • High-Definition Video Repair: Mends corrupted high-definition video footage including 4K, 8K, and up to 16K resolutions.
  • Software Support for Multiple Operating Systems: Works efficiently on both Windows and Mac operating systems.
  • Video Corruption Repair: Repairs video file corruptions or degradation caused by various factors ranging from virus attacks to unexpected system interruptions.
  • Audio-Visual Synchronization: Fixes out of sync audio and visual issues, ensuring a smooth playback experience.
  • Video Recovery Across Devices and Cameras: Recovers video files not only from traditional cameras but also from drones, dashcams, CCTVs, and third-party platforms.
  • Preview Option: Allows you to preview the repaired video before saving, ensuring satisfactory repair results.
  • High Success Rate: Provides a high success rate in video repair with up to 99.99% effectiveness.
  • Full Security: Ensures complete security during the repair process and guarantees that no data will be stored post repair.
  • Automatic Video Repair: Employs advanced AI algorithms for quick and automatic video repair.
  • Easy Three-Step Repair: Offers an easy three-step process – add video, load sample and click repair – for hassle-free video fixing.

Download:​

ASCOMP Backup Maker Pro 8.409 for Free

ASCOMP Backup Maker Pro is a powerful backup software that can make automated data backups with ease. It has secured encryption of up to 256 bits (AES) and it backs-up to USB drives/sticks, Cloud Storage, CD/DVD or WebDav. You can also choose full or partial backups.
  • Automatic backup at a specified time, at an interval or in the event of system events
  • Space-saving backup in the widely used zip format
  • Highly secure encryption with AES 256-bit
  • Supported target media: local disk, cloud storage, USB/flash storage, network (LAN), CD/DVD, web server (via FTP/FTPS)
  • Compatible with Windows XP, Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 and Windows servers

ThunderSoft PDF Converter Pro 6.0.0 - Free lifetime license

Features of Thundersoft PDF Converter:

  • PDF to File Conversion: Easily convert PDF files to various formats, including Word, Excel, PowerPoint, TXT, HTML, and images, making them editable and compatible with other applications.
  • File to PDF Conversion: Convert Word, Excel, PowerPoint, TXT, HTML, and image files into PDF documents, providing a simple way to create PDFs from different file types.
  • Encrypt PDF: Protect your sensitive PDF documents by encrypting them with a password, ensuring only authorized individuals can access the content.
  • Decrypt PDF: Remove the password from encrypted PDF files when needed, allowing you to access and edit the content without any restrictions.
  • Compress PDF: Reduce the file size of PDF documents without sacrificing quality, making it easier to share and store files efficiently.
  • Merge PDF: Combine multiple PDF files into a single document, streamlining information and improving organization.
  • Split PDF: Extract specific pages or sections from a PDF file, enabling better content management and sharing.
  • Edit PDF: Utilize the built-in PDF editing tool to modify text, images, and other data within the PDF document, providing flexibility in document customization.

ESET v20

This year's new v20 version is just around the corner. :)

Do you have any expectations about what it will bring? :unsure: