Normal view

There are new articles available, click to refresh the page.
Today — 12 August 2026Security/Privacy

Microsoft Plugs Nearly 400 Security Holes

11 August 2026 at 17:28

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Image: Shutterstock, Mallika Home Studio.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.

Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.

The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”

“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”

CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.

By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.

Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.

Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.

“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”

Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.

“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.

For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.

Kimwolf botnet rebuilt to survive takedowns, researchers say

By: Greg Otto
11 August 2026 at 20:13

The developers of a notorious botnet that’s powered mostly by hijacked Android TV boxes and other internet-connected devices have released a new version built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement, researchers at Palo Alto Networks said in a report published Tuesday.

The company’s Unit 42 threat intelligence group, which tracks the botnet as Kimwolf or Aisuru, said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet. 

The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today. A flood is the crude heart of a DDoS attack: thousands of infected devices send a target far more requests than it can answer. Rather than fire raw packets, this latest Kimwolf version operates with full browser fingerprints, copying the header order and behavior of the Chrome web browser. That matters because the usual defense against a flood is for tools to spot the fake traffic and drop or block it before it reaches the server. Traffic that looks like Chrome does not get dropped, so a site under attack must either serve every request and fall over, or start turning away the customers it cannot tell apart from the bots.

The second change, according to researchers, looks like it was done to withstand further takedowns. Every bot has to ask a command server for orders, which is also what authorities aim to disrupt in botnet takedowns. Normally, the command server address sits inside the malware as a web domain name, so investigators who take that name from its registrar are able to disrupt an entire botnet. 

This Kimwolf version moves its command beyond registrar controls. The malware now looks up its command address in the Ethereum Name Service, a directory that lives on the Ethereum blockchain. A web address using this service can display the way a normal domain does, but the domain’s record sits in a ledger copied across thousands of computers worldwide. The malware carries five public Ethereum services and shuffles the order before each attempt, making it harder for defensive tools to block. Additionally, there is no company to serve with a law enforcement order and no domain record to seize.

Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code. Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact.

Researchers’ infrastructure analysis pointed to the machines powering the command structure to be located in Russia. Four of these servers shared a SSH host key, with further analysis finding that the servers sit in one network registered in Saint Petersburg.

It’s unclear if this version was made by people behind previous iterations of the botnet, or a new person or threat group looking to capitalize on the botnet’s notoriety among malicious actors. 

Unit 42 did not respond to CyberScoop’s request for comment. 

Kimwolf, which splintered off from the record-setting Aisuru DDoS botnet last year, gained the widespread attention of security researchers when it temporarily claimed the top spot in Cloudflare’s global domain rankings in late October 2025. Previous versions of the botnet were disrupted by an international law enforcement operation in March that ended with Kimwolf’s infrastructure being seized.

A Canadian man alleged to run the botnet was arrested in May and extradited to the United States.
  

The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared first on CyberScoop.

Before yesterdaySecurity/Privacy

MS-DEFCON 2: Is Search going to get better?

6 August 2026 at 03:45
ISSUE 23.31.1 • 2026-08-06 By Susan Bradley The upcoming August updates include several promised fixes for Windows Search. The August updates will include several fixes, a few of which specifically target Search. I anticipate that the August updates will also bring a bumper crop of other vulnerabilities being patched, so I’m raising the MS-DEFCON level […]

Tracking the attacker

27 July 2026 at 03:22
ON SECURITY Tracking the attacker By Susan Bradley Recently, Apple, Adobe, Microsoft, and others released updates illustrating how much we are being impacted by AI. The three major vendors either sped up releases or released updates with a massive number of vulnerabilities. But does that make us more unsecure? Before I discuss some side effects […]

The patch apocalypse is here

20 July 2026 at 03:45
ISSUE 23.29 • 2026-07-20 PATCH WATCH By Susan Bradley Well, the benefits of AI are clearly here — at least in terms of bug counts. Microsoft fixed 621 vulnerabilities this time around. However, take a breath — a big breath. Even with all those fixes that encompass both Windows and .NET, the updates are pushed […]

Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed

15 July 2026 at 14:29

Democratic senators pressed President Donald Trump’s pick for director of national intelligence on questions of election security and integrity Wednesday, but they didn’t leave his nomination hearing satisfied with the answers.

As is typical for Trump administration nominees, Jay Clayton wouldn’t answer definitively at his Senate Intelligence Committee confirmation hearing whether Joe Biden won the 2020 presidential election, saying only that he was “certified,” while maintaining that he wasn’t an “election denier.”

He said that the Office of the Director of National Intelligence’s responsibilities were “principally” outside the United States. But he claimed varying degrees of ignorance about his predecessor, Tulsi Gabbard, being physically present at an FBI raid of a Georgia election office in January, and wouldn’t comment on its appropriateness.

Democratic senators were also frustrated while trying to pin down Clayton, the U.S. attorney for the Southern District of New York who served as head of the Securities and Exchange Commission in Trump’s first term, on remarks about mail-in ballots and the California primary election results last month.

Multiple senators, including Mark Warner, D-Va., Angus King, I-Maine and Mark Kelly, D-Ariz., tried to get Clayton to say whether Biden won the 2020 election. The final exchange came with Jon Ossoff, D-Ga.

Clayton protested that he had already answered. “I think I’ve answered the question,” he said. “We can keep doing this.”

Ossoff didn’t agree, telling him, “Well we’re going to keep doing it because you’re not being honest or forthright with the committee.”

“Isn’t it humiliating to be unable to answer this question?” he asked. “To have to indulge the president’s delusions? We know, you know, everybody in this room knows the truthful answer to that question. Why can you not give it?”

Earlier Clayton had said, “I’m not an election denier,” but repeatedly wouldn’t answer “yes” or “no” on whether Biden won in 2020.

That matters because of the DNI’s role, Kelly said, and it was worrying that Clayton was seeking to avoid upsetting Trump, who has maintained despite all evidence that he lost the 2020 election.

“It’s not about softening the edges when the truth is unpleasant,” Kelly said. “It’s about delivering information.”

Clayton discussed the DNI’s role on election security at greater length in pre-hearing written answers.

“I understand that the DNI, as head of the Intelligence Community, has substantial statutory authority to address national intelligence threats to U.S. elections,” he said. “In particular, the Director is responsible for the integration of national intelligence, which may include foreign intelligence threats to U.S. election activity. I also understand that Intelligence Community elements are authorized to cooperate with and provide appropriate intelligence and technical support to law enforcement agencies and that as head of the Intelligence Community, the DNI has oversight of those activities.”

A CNBC interview last month inspired some of the Democrats’ questions. Clayton said in response to questions about the California primaries that “On the integrity side, we’re doing an absolutely terrible job. And the American people are right to question it.” 

He said mail-in ballots present an “opportunity for fraud,” despite studies showing exceptionally low rates of fraud using that method, and said “mail-in ballots being used by one group and not another… honestly and dishonestly” was a “question that everyone is now asking.”

Sen. Ron Wyden, D-Ore., asked him about what group Clayton was referring to.

“”I would like to see where you’re pulling those quotes from. I’ve been very careful about my remarks on this,” Clayton answered. “I’d like to see the whole passage.”

In his questionnaire, when asked if “it would be inappropriate for a DNI to comment publicly about unsubstantiated claims regarding mail-in-ballots and election fraud,” Clayton answered that “If confirmed as DNI, any representations I make to the public, including about elections, will be informed by timely, objective national intelligence.”

Ossoff also had a tense exchange with Clayton when asking him about Gabbard’s appearance at the Fulton County office raid. Gabbard has said she was there because Trump asked her to be, in what subsequently became a highly publicized appearance because of questions about what the DNI would be doing at a law enforcement raid.

“I was made aware of it by you yesterday,” Clayton said.

Ossoff responded skeptically: “The first time you learned that Director Gabbard was present at that raid was in my office yesterday?”

Said Clayton: “It was the first time that in my recollection I’ve thought about it recently.”

“What?” Ossoff replied.

Warner, the top Democrat on the committee, told Clayton “I trust you” but it “strains credulity” that he wasn’t aware of Gabbard being at the raid.

“To be clear, the ODNI’s role is principally outside of the United States,” Clayton said.

On other topics, in his opening remarks, Clayton touted his SEC work on cybersecurity. In his questionnaire he said he would work to facilitate cyberthreat information sharing from his office.

He told Sen. Kirsten Gillibrand, D-N.Y., that he would evaluate whether the DNI should devote more resources to cybersecurity with federal government cyber experts being pushed out since Trump came back to office. Many Republicans are pushing to further reduce the size of Clayton’s office, contending it has become bloated beyond Congress’ original intentions as a coordinating body.

He said he supported renewal of Section 702 of the Foreign Intelligence Surveillance Act, which gives the executive branch controversial spying powers that Congress recently allowed to expire.

Trump has threatened to block renewal unless lawmakers advance his priority election bill. He said he will study how to “minimize the detrimental impact to our national security caused by the lapse in 702 authorities.” Some Democrats, meanwhile, have resisted action on the law until Trump’s pick for acting DNI Bill Pulte is gone, citing his prior efforts to investigate officials as head of the Federal Housing Finance Agency and lack of intelligence experience.

Because the GOP controls the Senate, Clayton is likely to get confirmed as DNI as long as no Republicans emerge in opposition. Wednesday’s hearing revealed no significant Republican objections.

Intelligence Chairman Tom Cotton, R-Ark., touted Clayton’s experience prosecuting terrorism cases and more.

“Jay Clayton has worked hand in glove with our intelligence agencies and counterterrorism personnel to lock up criminals who threaten our national security,” Clayton said. “I encourage my colleagues to join me and get Mr. Clayton’s nomination over the finish line.”

The post Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed appeared first on CyberScoop.

Windows K2: Microsoft’s reported plan to fix Windows 11

13 July 2026 at 03:44
WINDOWS 11 By Martin Brinkmann To fix a bloated Windows 11, Microsoft has reportedly launched “Project K2” — a massive internal repair campaign For years, Windows fans have watched Microsoft stuff the operating system with features barely anyone asked for, all while core features such as File Explorer, Windows Search, and the general reliability of […]

MS-DEFCON 2: More patches from Apple and Adobe

9 July 2026 at 03:45
ISSUE 23.27.1 • 2026-07-09 By Susan Bradley As a result of researchers’ using AI to do more in-depth code reviews of operating systems and applications, expect to see more security updates and more vulnerability counts. As Apple indicated to Reuters, the recent release of Apple security updates was done in an accelerated fashion because “… […]

Felons, Fraudsters Flog Offensive Cybersecurity Startup

8 July 2026 at 08:31

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X. “Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.”

The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.”

The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC. The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts.

A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia.

Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller, and Pete Buttigieg, then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris.

In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected.

In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement.

In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.

Jacob “Jay” Wohl’s GitHub account.

By the age of 17, Wohl had started multiple investment firms, and cultivated the nickname “Wohl of Wall Street” after appearing on Fox News in 2015 to discuss his new hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, and ordered him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and was sentenced to two years of probation.

The market for previously unknown security vulnerabilities has always been populated by a colorful mix of researchers, academics, charlatans, clout-chasers and people actively involved in cybercrime communities. But the market for selling offensive security services to the U.S. government tends to be far more circumspect. Plenty of government contractors recruit vulnerability researchers and pay for the exclusive rights to novel software exploits, yet none of them do so quite as brazenly and openly as IRIS C2.

Recent posts from the Twitter/X account IRISC2 (@c2iris).

Indeed, KrebsOnSecurity was unaware of IRIS C2 until last month, when an attendee at a regional cybersecurity conference shared that Wohl and Calvexa Group were pestering people at the conference about selling their vulnerability research.

In an interview with KrebsOnSecurity, Wohl said Mr. Burkman was not involved in the day-to-day operations of IRIS C2. Wohl shared that IRIS C2 originally began as a penetration testing company, but shifted its focus recently to selling phone-hacking services to the government. Several times throughout the interview, Mr. Wohl mentioned working on federal government contracts, but when pressed for specifics said he was not at liberty to speak publicly about them.

Mr. Wohl said he does not have any formal education or training in computer science or information security, and that most of his knowledge on the matter is self-taught.

“I know more about tech than anyone,” Wohl bragged. “My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”

Wohl said security researchers bring the company unique vulnerability findings “on a regular basis,” but that in many cases those findings are preliminary and not fully fleshed-out.

“Let’s say someone finds a flaw in a media decoder on a phone,” Wohl said. “A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do.”

Wohl claims IRIS C2 has approximately 40 employees, although he said none of them are allowed to list their employment on LinkedIn for operational security reasons. In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living. But if IRIS C2 has any other employees, they may be similarly unaware of Mr. Wohl’s history of outright fabrications — or even his real name.

In September 2024, Politico reported that Burkman and Wohl were bragging about big companies supposedly buying services from their now-defunct company LobbyMatic, which claimed to use artificial intelligence to assist in political lobbying efforts. However, Politico found the pair were running the company using pseudonyms, with Wohl reportedly adopting the name “Jay Klein” and Burkman using the moniker “Bill Sanders.” Politico reported that two of the former LobbyMatic employees resigned after learning of their true identities, while other employees only learned after they had left the company.

Update, July 9, 9:44 a.m. ET: Several readers pointed our attention to a March 31 publication from journalist Molly White, which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a “presidential pardon to avert a miscarriage of justice” on behalf of the accused hacker, who has not yet been convicted.

June 29, 2026 Apple Updates

By: PKCano
30 June 2026 at 04:00
On June 29, 2026, Apple released Updates for MacOS Tahoe 26.5.2 and iOS/iPadOS 26.5.2. Apple is expected to release the next version of their Operating Systems, v26.6, in early July. Normally they package the Security Updates along with the new versions. But,  as reported by Reuters, Apple is releasing the updates early for macOS/iOS/iPadOS in […]

What to do with older tech

29 June 2026 at 03:42
ON SECURITY By Susan Bradley When I started writing this column, I planned to open with the forthcoming end of the Windows 10 ESU. Oops. On June 24, Microsoft changed its mind. It decided to extend the Windows 10 Extended Security Updates (ESU) program for another year, until October 12, 2027. You can find the […]

Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks

By: BHIS
24 June 2026 at 10:00

Insufficient egress filtering is a commonly identified vulnerability found during BHIS penetration tests. The insufficient egress filtering finding indicates that network traffic leaving the organization’s environment is not properly restricted.

The post Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks appeared first on Black Hills Information Security, Inc..

Controversial FISA spying law expired this week. The spying will continue.

By: Dissent
14 June 2026 at 08:12
On June 12, Jon Brodkin reported: Title VII of the Foreign Intelligence Surveillance Act (FISA) is set to expire at midnight tonight after Congress failed to pass an extension of the controversial spying law. But that doesn’t mean the government’s spying powers will disappear. Surveillance under Section 702 of FISA “operates under yearlong certifications approved...

MS-DEFCON 2: Fixes for Windows 11

4 June 2026 at 03:45
ISSUE 23.22.1 • 2026-06-04 By Susan Bradley Microsoft is starting to roll out its much-promised, dribbled fixes. Included in the upcoming June updates — and already included in the preview updates released on May 26, 2026 — KB5089573 includes the Secure Boot fixes and the beginning of many changes about which you’ve complained. Nonetheless, it’s […]

European authorities crack down on illegal streaming networks

3 June 2026 at 18:15

Authorities in Europe arrested 29 alleged cybercriminals and took down more than 27,000 illegal streaming URLs that pirated major sporting events, films and TV programming, Europol said Wednesday.

The continent-wide collaboration, led by Bulgaria and the European Union’s police agency, allowed authorities to dismantle nine organized crime groups supporting the illicit streaming networks, officials said. “Operation Kratos 2” focused on disrupting the networks’ underlying infrastructure and stretched for seven months before coming to a close in April. 

Officials did not name the suspects, groups or services targeted during the crackdown, but noted that investigators identified key players responsible for managing and operating the piracy platforms.

Europol said the streaming sites infringed on nearly 850,000 media across 169 domains. 

“What appears to consumers as cheap access to premium content is powered by complex criminal enterprises,” the agency said in a news release. Illegal streaming site operators host separate servers for customer-facing websites and illegal content, and distribute their services across multiple countries.

During the course of the operation, officials conducted 148 house searches, identified 86 suspects and referred 59 cases to courts for criminal proceedings. 

Investigators also worked with private-sector partners to identify nearly 4,400 new domains and more than 18,000 IP addresses linked to piracy and other illegal activity. Those efforts allowed authorities to report almost 400,000 additional URLs for suspension or removal. 

Live sports piracy networks are widespread and consistently tracked by antipiracy coalitions and authorities globally. Authorities in Egypt last year shut down Streameast, the most popular and largest illegal live sports streaming network at the time, with an operation that spanned 80 domains and logged more than 1.6 billion visits during the year prior.

Operation Kratos 2 was supported by anti-piracy associations, UEFA Europa League, La Liga, beIN Media Group and officials from Belgium, Bulgaria, Croatia, France, Greece, Ireland, Italy, the Netherlands, Poland, Romania, Spain, the United Kingdom and the United States.

The post European authorities crack down on illegal streaming networks appeared first on CyberScoop.

Snapdragon X2 is fast, but Windows on Arm holds it back

25 May 2026 at 03:44
SILICON By Matthew S. Smith Qualcomm’s Snapdragon X2 chips are mighty, but Windows on Arm can still be a mighty pain in the neck. In May 2024, I took the train up to Seattle for Microsoft’s Build developer conference. It’s usually a series of nerdy talks from passionate developers that end up overshadowed by hyper-corporate […]

MS-DEFCON 2: Sometimes there’s no fix

7 May 2026 at 03:45
ISSUE 23.18.1 • 2026-05-07 By Susan Bradley It’s time to prepare for the May updates, which includes pausing and deferring them. That’s why the MS-DEFCON level is going to 2. There may be some confusion about the recent changes to the level. You’ll recall that I changed the level to 4 on April 28 and […]
❌
❌