❌

Normal view

There are new articles available, click to refresh the page.
Today — 26 September 2026Main stream

The Aosu R1 Ultra is a great subscription-free video, albeit with some minor flaws

Aosu Video Doorbell R1 Ultra: two-minute review

Doorbell brands usually sell you the hardware cheap and charge you monthly for the privilege of seeing the footage. Aosu has gone the other way, and for that alone the R1 Ultra is worth your attention.

Video clips go to the AosuBase Mini, a small plug-in box that lives inside your house and does three jobs at once — Wi-Fi bridge, indoor chime, and storage. It holds 8GB and keeps a rolling 60 days of footage.

There is an optional cloud subscription, AosuProtect+, but unlike Ring's arrangement, the doorbell isn't hobbled without it. You get alerts, live view, two-way talk, custom detection zones, and full playback for nothing other than the purchase price.

Aosu Video Doorbell R1 Ultra on stone surface

(Image credit: Future)

Detection is another strength. Rather than relying on a passive infrared sensor and hoping, Aosu layers radar and AI human recognition on top, which lets it judge distance and intent — approaching versus passing, lingering versus walking through.

There's also a Tone button hiding in the two-way talk screen. Tap it, and you can answer the door as either 'uncle' or 'clown', with Aosu's straight-faced explanation that this disguises your voice for privacy.

The uncle setting artificially deepens voices, transitioning women and children to something resembling a man to deter would-be intruders. Clown goes all high-pitched and distorted to mask your identity.

Aosu Video Doorbell R1 Ultra screengrab from app

(Image credit: Future)

Fortunately, the latter falls on the right side of sinister, so you can forget scaring off trick-or-treaters with imitations of South Park’s Mickey Mouse.

Where Aosu gets ahead of itself is resolution and framing. The sensor is 2560 x 1920, which is 4.9 megapixels in a 4:3 frame. That’s sharp, and a step up from 2K doorbells at this price, but not the claimed ‘UHD’, which would be 3,840 x 2,160.

The asserted 60% improvement over standard 2K only holds if the 2K you're comparing against is Aosu's own 3MP doorbell. An earlier version of the identical claim, on the identical camera, said 40%.

Screengrab of footage in Aosu Video Doorbell R1 Ultra app

(Image credit: Future)

Field of view should be taken with a pinch of salt, too. Aosu says 166 degrees, but that's the corner-to-corner measurement. In reality, it's 133 horizontal by 103 vertical, shot in a shallow 4:3 aspect ratio and no head-to-toe image tricks.

With realistic use, the battery should last six months between charges. The kicker is the cell isn’t quick-release, and juicing it from flat to full takes six hours. So that means unclipping the entire doorbell and going without it for quite a while.

Aosu Video Doorbell R1 Ultra: price & availability

  • List price: £139.99 / $135.99 (about AU$190)
  • Launched July 2026 in the UK
  • Available in the UK, US, and across the EU

With a list price of $135.99 / £139.99 (about AU$190), but usually discounted, the R1 Ultra is filed under ‘affordable’ and veers towards bargain territory if you find one hovering around the £100 mark.

At that price, the value case is strong, because the base station is in the box rather than a £50 upsell, and the 60 days of local recording would cost you a subscription almost anywhere else.

Over three years, that's the difference between a hundred pounds and several hundred more.

  • Value score: 4/5

Aosu Video Doorbell R1 Ultra: subscription costs

The R1 Ultra is fully functional without a subscription. Alerts, live view, two-way talk, detection zones, and 60 days of local playback are all included.

AosuProtect+ is the optional cloud add-on. In the UK, it's advertised at £9.99 (about $10 / AU$20) a month or £122.99 (about $160 / AU$230) a year, currently discounted to £3.49 (about $5 / AU$10) and £39.99 (about $50 / AU$80). Treat the higher figures with the same suspicion as the hardware list price.

The annual price is simply the monthly rate multiplied by twelve, so there's no built-in saving for paying up front, and £3.49 lands within pennies of what Aosu charges in dollars in the US. There’s a 30-day free trial if you wish to dip your toe.

Aosu Video Doorbell R1 Ultra subscription details in app

(Image credit: Future)

What it buys you is cloud backup rather than capability: 14 or 30 days of event recordings, playback from anywhere, faster scrubbing, and bulk downloads. AI facial recognition sits on the top tier and is offered for video doorbells only.

The argument for paying is that local storage is bound to the base station like Bilbo Baggins is bound to the ring in The Lord of The Rings. If it fails, someone takes it, or you inexplicably drop it in the fires of Mount Doom, your footage dies with it.

Aosu Video Doorbell R1 Ultra: specs

Feature

Specification

Type

Battery-powered or hardwired video doorbell; base station required

Resolution

5MP (2560 x 1920) with WDR

Zoom

6 x digital

View

4:3 aspect ratio

Field of view

166 degrees diagonal [133 x 103 degrees]

Night vision

Infrared up to 6 feet / 10m

Audio

Two-way talk with voice disguise features

Motion detection

Radar, PIR and AI human recognition; customizable zones

Power

Rechargeable battery 5,000mAh, non-removable; USB-C cable included; 6 hours from flat; hardwire (8–24VAC)

Connectivity

Doorbell 2.4GHz only; AosuBase Mini dual-band 2.4GHz / 5GHz

Smart detection

AI human recognition; facial recognition requires AosuProtect+

Storage

Local, 8GB on AosuBase Mini, 60-day loop, no subscription; optional cloud with AosuProtect+

Smart home

Amazon Alexa, Google Assistant

Tamper protection

Pry detection with chime alert; footage retained locally

Weather

IP65

Finish

Black/silver

Dimensions

5 x 2 x 3 inches / 12.7 x 5.1 x 7.6cm

Aosu Video Doorbell R1 Ultra: design and installation

  • Plain but solid
  • Hub required indoors
  • Battery or existing wiring

The R1 Ultra is a black plastic slab with silver flourishes similar to a Ring, and very little design ambition beyond flattering imitation.

Installation is straightforward and takes about half an hour all in. Bracket on the wall, doorbell clipped on top, base station plugged in somewhere central.

Aosu Video Doorbell R1 Ultra with accessories straight from box

(Image credit: Future)

Aosu recommends mounting at 4 feet / 1.2 meters rather than eye-level, which is lower than instinct suggests but necessary if you want the frame to reach the doorstep. Worth getting right the first time rather than re-drilling.

A 15-degree wedge is included if you need to angle it towards a path or a gate, along with a screwdriver, extension wires and wire nuts for anyone hardwiring to existing 8–24V doorbell wiring.

The base station isn't optional, and it isn't outdoors-rated. It's the storage, the chime, and the Wi-Fi bridge in one. It needs a mains socket permanently, and it's rated only to 14°F / −10°C, so it lives in the hall or the cupboard under the stairs and stays there.

Aosu Video Doorbell R1 Ultra chime plugged in

(Image credit: Future)

Detaching the whole unit from the wall for a full six-hour recharge via USB-C is a weak point, but a cable is bundled in the box.

A neat addition is pry detection. Try to lever the unit off its bracket, and it sounds a chime and pushes an alert, with footage on the base station indoors rather than on what’s being stolen.

  • Design score: 3.5/5

Aosu Video Doorbell R1 Ultra: performance

  • Sharp in daylight
  • Strong multi-sensor detection
  • Infrared-only after dark

Daylight is this doorbell’s happy place, with 5MP more than most similarly-priced rivals offer. Faces, delivery uniforms and parcel labels are legible rather than merely present.

Radar handles distance and movement, PIR picks up body heat, and the AI layer decides whether what it's looking at is a person. During testing, alerts felt instantaneous once someone reached the door.

After dark, expectations need managing. There is no color night vision and no spotlight.

Footage from Aosu Video Doorbell R1 Ultra in app
Future
Aosu Video Doorbell R1 Ultra footage in app
Future
Night time footage from Aosu Video Doorbell R1 Ultra in app
Future

Eight 850nm infrared LEDs offer monochrome up to 33 feet / 10 meters, and the manual warns mounting too close to a side wall will bounce IR back into the lens and fog the image. I’d pair the R1 Ultra with an outdoor light to make up for the shortfall.

Answering the door is well handled. Notifications arrive with a thumbnail of whatever triggered them, so you can tell a courier from a cat without opening the app, and tapping through starts a proper two-way video call rather than a one-way stream.

The 6x digital zoom lets you crop into a face or a label, though at 15fps and with a wide lens, it softens quickly.

Aosu Video Doorbell R1 Ultra footage in app
Future
Footage from Aosu Video Doorbell R1 Ultra in app
Future

Quick Reply issues an audible preset message when you can't talk. Somewhat boringly, they’re fixed, so you can’t edit the wording or add your own.

On connectivity, the doorbell itself is 2.4GHz only; the dual-band capability belongs to the AosuBase Mini, which talks to your router on 2.4 or 5GHz.

That's a sensible design for a battery device, but it means the camera-to-base link is on the crowded band and placement of the base matters more than usual. Plugged in 33 feet / 10 meters from my front door with the broadband router halfway, all was fine.

Live view includes a UHD/SD toggle to drop the quality when the connection struggles, and you can save a clip or a still straight to your phone's camera roll if you ever need to hand something to a neighbor or the police.

The six-month battery figure assumes up to ten events a day at 20 seconds each — about three-and-a-half minutes of recording daily. On a busy porch with a path or pavement in frame, expect considerably less.

  • Performance score: 3/5

Should you buy the Aosu Video Doorbell R1 Ultra?

Attribute

Notes

Score

Value

Local storage, included base station, and no monthly fee at around £100 make the maths hard to argue with.

4/5

Design

Solid and easy to install, but the base station needs a permanent socket, and recharging equals doorbell removal.

3.5/5

Performance

Sharp daylight video and excellent multi-sensor detection, let down by infrared-only night vision and overstated specs.

3/5

Buy it if

You're sick of subscriptions

Sixty days of local recording on the included base, with nothing important behind a paywall, is undoubtedly attractive.

You'd rather not be yourself

Uncle and clown voice settings let anyone home alone answer the door sounding like someone else.

You want fewer useless alerts

The radar, PIR, and AI combination is a real step up from the single-sensor budget crowd, and it shows in your notification tray.

You have existing doorbell wiring

Hardwiring to 8–24V takes the recharging problem off the table entirely, and this is one of the cheaper doorbells that supports it.

Don't buy it if

You need to see faces after dark

Infrared monochrome to 33 feet / 10 meters is all you get. There's no spotlight and no color low-light mode, so a night clip tells you someone was there, but not necessarily who.

You don’t want to remove the doorbell

No quick-release battery means every recharge is a six-hour outage with the unit off the wall and on your kitchen counter.

Aosu Video Doorbell R1 Ultra: also consider

Ring Battery Video Doorbell (2nd Gen)

Cheaper, shoots Retinal 2K with a genuine head-to-toe 1:1 view and color night vision, and installs without a hub. The trade-off is Ring's subscription model and Amazon's data record.

Eufy Video Doorbell C31

The closest like-for-like on the no-monthly-fee promise, with 2K video and a quick-release battery, though you'll want a HomeBase to get the most from it.

How I tested the Aosu Video Doorbell R1 Ultra

  • Fitted to a domestic front door
  • Assessed daylight and infrared video, detection accuracy, and audio
  • Ran entirely without a subscription


I mounted the R1 Ultra on my own front door and used it as the household's main entry camera for a fortnight, deliberately running it on local storage alone so the no-subscription claim could be tested as most buyers will experience it.

I checked live-view responsiveness and alert latency, reviewed clips in daylight and after dark, and tracked battery drain against Aosu's 180-day claim.

First reviewed September 2026

Bitdefender first to launch free 'temporary' VPN for AI Agents because they're worth it — but you can only use it on Apple M-series Macs for now

  • Bitdefender launches privacy tool built specifically for autonomous AI agents
  • Each agent task gets a disposable, temporary connection that deactivates when the task is done
  • VPN for AI Agents runs on a Model Context Protocol server architecture entirely

Bitdefender has introduced VPN for AI Agents, a standalone privacy tool built specifically for the autonomous software agents now browsing, researching, and transacting on behalf of everyday users.

The company says this public beta is a direct answer to the growing anxiety over machine-driven data exposure.

Unlike a conventional privacy tool that stays connected at all times, this tool activates only when an AI agent needs it, then deactivates once the task is done.

Why agents need their own privacy layer

Cybersecurity researchers have increasingly warned that autonomous agents occupy an ambiguous identity space, often borrowing a person's own credentials or shared workload logins to complete tasks online.

Without a clear separation, every website an agent visits and every transaction it completes remains traceable back to a single household IP address.

Recent Pew Research Center data found 71% of adults in the United States believe wider AI adoption will make their personal data less secure, a fear that extends well beyond American borders.

Bitdefender's new offering, built on a Model Context Protocol server architecture, spins up a disposable digital workspace for each prompt and discards it when the task is done.

Each prompt opens its own encrypted tunnel and exits through the VPN server's IP address, so no cookies, cache, or session state carries over to the next task.

The tool covers network transport and IP masking only, leaving the actual content of a prompt exchanged directly between the user and whichever AI provider is running it.

"AI agents are quickly becoming an extension of the people who use them, showing up in both our workdays and our personal lives," said Ciprian Istrate, senior vice president of operations, Consumer Solutions Group at Bitdefender.

"That means security can no longer stop at protecting the person behind the screen; it has to extend to the agent itself acting on their behalf."

This approach treats each agent like an independent team member requiring its own security boundary rather than inheriting the user's existing protections wholesale.

Bitdefender also describes this as clean-IP browsing, useful for QA checks on pages that display different content depending on the visitor's country.

The tool supports up to four simultaneous exit locations, or eight under the recommended testing configuration.

Access remains limited during the beta period

For now, the tool works only on macOS devices, though Bitdefender has confirmed plans to expand to additional operating systems after beta testing.

The beta specifically requires macOS 13 or later and an Apple silicon processor, meaning Intel Macs are not supported.

Bitdefender recommends macOS 15, 16 GB of memory, and roughly 10 GB of free disk space for smoother testing.

Once installed, it operates automatically across several popular AI platforms, including Claude Desktop, Cursor, Codex, and OpenCode, without requiring manual configuration from the user.

Bitdefender lists several practical use cases, including letting an agent compare prices across regions or complete multi-country research in one session.

The company frames these tasks as a productivity gain too, since they would otherwise need manual, country-by-country effort from a person.

Bitdefender is explicit about the tool's limits as well. It does not protect a device's other apps or browser.

It also does not hide prompts from the AI provider running them, and does not override a site's terms of service, rate limits, or an existing IP ban.

"With Bitdefender VPN for AI Agents, we're giving students, workers, and everyday consumers the confidence to let their AI agents work freely, knowing their identity and activity stay protected," Istrate added.

VPN for AI Agents public beta is currently available for free, but whether the free offering continues after the beta testing remains to be seen.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Amnezia VPN boosts stability of all apps with a new update

  • AmneziaVPN rolls out version 5.0.3.0 across all apps
  • It brings new XRay-core, TProxy, and minor user updates
  • It includes upgrades for Self-hosted and Premium users

Anti-censorship Amnezia VPN has released a new app version that improves stability, introduces an updated Xray-core, and brings updates for both self-hosted and Premium users.

The move comes after the VPN provider spent months strengthening its security measures to counter the attacks launched by Russian organisations that specifically targeted the best VPNs operating in the region.

Version 5.0.3.0 is available on all devices (version 5.0.3.1 for Android); users can download it from the Amnezia website, GitHub, and the Android and iOS app stores.

Amnezia VPN — censorship-resistant VPN
Amnezia VPN is an affordable, privacy-focused service that prioritizes essentials like security and censorship unblocking over unnecessary extras. All its apps are open-source, albeit more basic than some competitors. It offers both Free and Premium protection, with the latter billed at $28 for six months and $48 for a year. You have 14 days to decide if you like it or not, risk-free, thanks to its money-back guarantee. View Deal

Amnezia VPN 5.0.3.0: what's new?

Rather than a major update with dramatic new features, the new version emphasises general clean-up, maintenance and connection stability.

For example, the XRay protocol, the core component of the proxy that allows users to bypass censorship, has been updated from version 1.3 to 1.4, in line with the adoption of a newer protocol system in the new version.

Additional support for the TProxy container has also been introduced. The Linux support is useful for routing traffic through the VPN at the transparent proxy level, essentially allowing Linux systems to make the traffic appear as if it originates from the user, thereby making it more difficult to block WireGuard connections.

The update also enables self-hosted users to set up a proxy for Telegram by directly going to the “Self-hosted” section to install it.

⚡️The new app version 5.0.3.0 is here.It is now available for all devices (version 5.0.3.1 for Android). Download it from our website or directly from your app store.In this release, we have improved connection stability, updated Xray-core, and added several important updates…September 22, 2026

For Premium users, the VPN has also improved performance when connecting via the VLESS anti-censorship routing protocol.

Additional fixes addressed Android warning log levels, alongside self-hosted default values, links, and other minor issues that have been corrected.

In terms of user changes, the new release includes a Google Play billing library, which was added as a small feature component to handle In-App Purchases (IAP), and a new country was added to the supported dataset, overall boosting the user experience with minor tweaks.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Relentlessly updating

Amnezia's efforts to combat censorship had largely focused on previous updates, designed to strengthen its anti-detection capabilities in response to the Russian government's increasingly sophisticated Internet censorship regime.

In June, the open-source VPN said it fixed a bug in its AmneziaWG protocol that had previously left its infrastructure vulnerable to a coordinated cyberattack, allegedly carried out by Russia's media regulator, Roskomnadzor (RKN).

In August, the VPN focused again on security by updating its anti-censorship protocol, AmneziaWG, introducing greater variability in traffic patterns to increase the VPN’s invisibility against new detection methods. During the same month, the provider also strengthened its blocking capabilities with a 'mandatory update' for Premium and Free users.

The move came after a crackdown by the government blocked access to more than 20 widely used privacy services, with the scale of the attack suggesting that Roskomnadzor is continuing to boost new sophisticated ways to filter VPNs.

These governmental repressive measures are making it increasingly difficult for citizens to access the free internet. Additionally, the more repressive these attacks are, the more they seem to influence citizens' perception of VPNs as an everyday tool they need, rather than the opposite.

Indeed, research recently showed that they are developing new forms of collaboration to use VPNs, and view the associated costs as just as essential as those for mobile Internet and routine bills.

This Mac malware is somehow using iCloud calendar invites to try and steal your data

  • Kaspersky uncovers MacSync, a Mac infostealer delivered via iCloud calendar events and fake apps
  • Loader fetches instructions from calendar entries, then deploys malware exfiltrating credentials, wallets, and developer data
  • Newer variants add Objective‑C backdoor spoofing Finder, persistence, and expanded targeting of crypto and IT users

Cybercriminals have found a way to use iCloud calendar events and cloud storage to deliver a powerful infostealer to Mac devices.

The malware is called MacSync, and it’s hiding behind fake crypto wallets, or “cracked” commercial software.

Security researchers Kaspersky, who discovered the ongoing campaign, are urging Mac users to exercise caution when downloading programs, especially from third-party websites, and to be very skeptical of apps prompting for their admin password.

Why calendar?

Getting people to download and run malware on their devices is not as easy as it sounds.

The victims need to be somehow tricked into downloading and running an app, and even when they do so, chances are the malicious program will be sniffed out by whatever antivirus solutions the device has running, before it can do any meaningful damage. Also, crooks don’t want to be forced to repeat the process every time they want to deploy a different variant, or type of malware.

So, they resort to all sorts of techniques and workarounds, from DLL sideloading, to malware loaders.

By separating the initial infection and the actual malware, cybercriminals can reduce detection rate and get more flexibility, but it creates a new problem: defenders can monitor the traffic going in and out of different apps and thus detect when a loader is deploying malware.

The challenge then becomes hiding the traffic, and MacSync does it by using the iCloud calendar.

After being downloaded and executed, the loader will reach out to the calendar - which is a totally benign activity that is unlikely to raise any suspicion - and look for a specific public event, pre-built by the attackers. In its description, it will find the instructions, and the location of, the actual infostealer, and deploy it to ultimately compromise the target device. In this case, the location was also in the iCloud.

The loader itself is being advertised through social media, SEO poisoning, and phishing. Victims are directed either to fraudulent websites or social media channels promoting cracked software, or free versions of advanced solutions. In at least one example, Kaspersky saw the loader being advertised as a cryptocurrency wallet. Victims are shown a typical ClickFix error, and told to fix it by pasting a command in the Terminal.

The command deploys the loader which, in turn, installs MacSync.

A "substantial" overhaul

The infostealer emerged in April 2025, and was initially spun out of AMOS, one of the most popular information-stealing variants for the MacOS. It is based on Swift and has, since then, evolved to offer additional capabilities. According to Kaspersky, it can exfiltrate browser history, cookies, saved credentials, cryptocurrency wallet and app data, Telegram data, Keychain data, as well as system and device information. It can exfiltrate SSH, AWS, Kubernetes, Git, and shell configuration files, as well.

Newer variants come with an Objective-C backdoor spoofing the macOS default file manager, Finder. It establishes persistence, terminates notification processes to prevent alerts, and grants the attackers backdoor access, including running AppleScript received from the C2 server, deploying browser extensions, replacing the legitimate Ledger wallet app, collecting additional system information, and more.

Kaspersky also found an undefined command called “live_browser”, which downloads and runs a component named “sn_relay”, whose point has not yet been established.

The new versions “significantly” differ from older ones, Kaspersky said, stressing that the attackers “substantially” overhauled their approach.

“The nature of the data attackers seek to collect from a victim’s device, as well as the categories of applications the stealer disguises itself as, clearly indicates that this malware family primarily targets developers, crypto enthusiasts, and other users associated in some way with IT and the crypto space,” the researchers stressed. “MacSync’s compromise of software developers’ devices poses particular security risks for both end users and corporate systems, opening up expanded opportunities for attackers to further their intrusion.”

The full list of indicators of compromise (IoC) can be found on this link.

'Decades-old' bugs found affecting Windows, Android, macOS and Linux — but the OS makers don't see it as a big deal

  • Graz University researchers found decades‑old flaws in file‑notification subsystems across Linux, Windows, macOS, and Android
  • Side‑channel attacks can infer keystrokes, visited websites, or even steal credentials via unprivileged access
  • Linux shipped partial mitigations (CVE‑2025‑68788); Microsoft and Apple acknowledged but did not patch, demo expected at ACM CCS 2026

Researchers have found a vulnerability in all major operating systems which could, in certain scenarios, allow threat actors to steal login credentials, or track which websites the target is visiting. OS makers, on the other hand, don’t seem all too phased about it.

The bug is described as a side-channel attack - a type of attack in which threat actors simply observe how the system operates and extract valuable secrets through indirect clues. For example, by monitoring how much power the chip takes at any given moment in time, attackers can observe and extract passwords.

It was discovered by security researchers from Austria’s Graz University of Technology: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast, and Daniel Gruss.

Notifying the system

This particular side-channel vulnerability was found in the file-notification subsystem running in pretty much every OS in existence today. The subsystem is built to notify applications when files on a system change. Not what has changed, just that a change occurred. The bug is allegedly quite old, too.

"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change," said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to The Register.

On Linux, the subsystem is called inotify and it’s been affected since 2005. On Android it’s FileObserver (affected since 2008), and on Windows - ReadDirectoryChangesW - flawed since the year 2000. On MacOS, it’s called FSEvents, vulnerable since 2007.

In the paper, the researchers claim file event information can help attackers conclude what other users on a computer are doing. They can launch an inter-keystroke-timing attack, inferring what users are inputting (both locally and remotely), reveal which websites they visit, and possibly even steal login credentials through UI redress.

The problem stems from the fact that unprivileged users are allowed to access the file notification subsystem. This primarily relates to files that can be read by multiple users, but apparently, there are quite a few files on a system that fall into that category.

No patch

"On Linux, watching a readable directory leaks events on files inside it you cannot even read: watching /dev/input gives a notification on every keystroke, which we turn into a local inter-keystroke timing attack with a 93.1–100% [keystroke accuracy] score across seven users and a remote (SSH) one at 100%,” Neela said.

The percentage range means the attack won’t work in all cases, which is more-or-less standard with side-channel attacks. They are notoriously difficult to pull off, which is also likely why most OS makers barely flinched at the news.

All of them were notified of the findings roughly a year ago, and most of them never bothered to address it. Linux introduced some mitigations, including CVE-2025-68788, which prevents inotify from generating certain “access” and “modify” events for special files. The fix was shipped to multiple kernels and Linux distros, but it addresses only part of the broader attack techniques that the researchers described.

Microsoft and Apple apparently acknowledged the findings, but apart from that - did very little. Microsoft told the researchers the behavior of ReadDirectoryChangesW was "by-design", although the feature is undocumented. They believe the ability to monitor file paths across users is not a vulnerability worthy of a patch. The report does not mention Apple doing anything about it, either.

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script

25 September 2026 at 15:13
Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad that also included the exact script they had to read during these scam calls. This and other true-crime tales of criminals making fools of themselves appear in the latest installment of the Trellix Advanced Research Center’s Dark Web Roast, which uses memes and mockery to troll criminals on the dark web. It also acknowledges: “While these incidents are genuinely amusing, they represent real criminal activities causing significant harm.” One of these incidents from August involves a Telegram user identified by Trellix as Derian (@crɑick) who posted an ad in the UK Fraudsters Telegram channel. “Hiring - Female/Male Mail Callers,” the advertisement said, seeking “USA/CA (white sounding)” applicants and, in bold, “NO SCRIPT READING.” The ad then proceeded to print the exact script the callers would read: “Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with Larry Boyles?” The Trellix threat-intel analysts note that the “‘recorded line’ flourish is a nice touch, because nothing says legitimacy like a fraudster cosplaying compliance theatre. The pretexting playbook is depressingly effective, but the recruiter’s QA process is roughly as robust as the fake Google team it impersonates.” Burn, baby, burn. The Register previously spoke with Trellix VP of threat intelligence strategy John Fokker about the Dark Web Roast, and he said the idea came from a desire to take an "almost psyops" approach to covering the criminal underground. "We don't want to glorify them, what's the opposite we can do? We're going to roast them," Fokker told us during a conversation at RSAC. "I'm trying to spark a debate, or a healthy conversation, about what we can do as an industry," he said. "Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers." The FBI’s Internet Crime Complaint Center (IC3) recently reported its most damaging year for internet scams, with 2025’s data pegging reported losses at $20.87 billion, and English-language social engineering is among the most in-demand skill sets on underground forums. One report by threat detection and response firm ReliaQuest found the number of job advertisements posted on criminal marketplaces mentioning this particular talent more than doubled between 2024 and 2025. Plus, according to Google, voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate – and the No. 1 tactic used when breaking into cloud environments. So when these criminals do dumb things, we’re happy to see Fokker’s team call them out.®

Crooks use fake desktop apps to fool HR staff into giving them remote access

25 September 2026 at 13:29
You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual web interface, you grab it. Unfortunately, the app isn't what it claims to be. Instead, it silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to your PC. Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and other remote monitoring and management software. This time, the main giveaway is knowing what the vendors actually sell: None offers the Windows app being advertised. According to Allure, the campaign impersonates three unnamed US-based HR and payroll platforms by offering fake desktop clients for those providers’ software. In all three cases, those companies don’t offer a desktop client, meaning all it takes is an unaware HR or payroll clerk tricked by promises of superior performance to potentially expose some incredibly sensitive company data. Allure said that it’s not sure how potential victims are being targeted by the campaign either, but those who have been targeted may not pick up on anything being wrong. Clicking through to the website offering the fake app brings up a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host’s bot challenge page, meaning scrapers haven’t been able to index it and expose the scam. Further obscuring the malicious nature of the campaign, the downloads are hosted on a GitHub Releases page, meaning they point to a trusted domain. Once downloaded and executed, the installer presents the victim with an actual Microsoft installer to make it appear like a legitimate piece of software. It actually installs the Microsoft .NET Desktop Runtime 8.0.26, so it goes through the entire process and shows that an installation completes, but nothing ever pops up, leaving the victim unclear as to where their desktop app went. That’s not all the installer is doing, of course: It’s also running a quiet, no-interface installer to drop the ScreenConnect client on the victim’s machine. “The [ScreenConnect] access mode is set to unattended,” Allure notes. “The victim-facing indicators are turned off: no ‘your machine is being controlled’ banner, no system-tray icon, no connection balloon.” The silent install is also configured to launch on boot, and stay connected across various user sessions, giving the attacker “a quiet, persistent, interactive foothold,” says Allure. “Nothing in this chain is malware in the usual sense,” the infosec outfit said. “The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it.” In other words, security teams have some work to do before they even check the indicators of compromise that Allure included in its report: Check with HR and payroll vendors to see if they offer a desktop app, and if not alert all members of those teams to this campaign. For those hoping they haven’t fallen victim, the actual number of victims remains unknown. Allure said the GitHub download counts across the three fake downloads totaled 291 as of its report. Some of those came from Allure’s researchers, and possibly other researchers and sandboxes too, so the download count can’t be used to determine how many victims there are. ®

Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

25 September 2026 at 17:28

A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice Department said Friday.

Cameron John Wagenius engaged in a cybercrime spree for years, including while he was on active duty on a base in Texas. Prior to his arrest in December 2024, Wagenius attempted to sell stolen sensitive data to a foreign intelligence service and sought information online about defecting to Russia.

“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” said A. Tysen Duva, assistant attorney general of the Justice Department’s Criminal Division, said in a statement.

Wagenius, who pleaded guilty in July 2025, leaked stolen call records of President Donald Trump as part of multiple failed attempts to extort $500,000 from AT&T, Allison Nixon, chief research officer at Unit 221B, previously told CyberScoop. 

Authorities did not name Wagenius’ alleged victims in court filings, but said he disclosed non-content call detail records belonging to a government official and family members of another former official. AT&T in July confirmed cybercriminals accessed the company’s Snowflake environment in April and stole six months of phone and text records of “nearly all” of its customers. 

Wagenius’ and one of his co-conspirators, Connor Moucka, attempted to extort more than 10 organizations after stealing credentials and breaking into cloud platforms used by AT&T and other major companies based in the United States and abroad. 

Moucka, a Canadian extradited to the United States in March 2025, pleaded guilty in August to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion.

Wagenius, Moucka and their alleged co-conspirator John Erin Binns, who is not presently in U.S. custody, stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts and Santander.

Some of the records in Wagenius’ possession at the time of his arrest were stolen in the attack spree on Snowflake customer databases, according to cybercrime researchers. Officials said Wagenius was directly involved in attempted extortion attempts targeting multiple organizations for a combined total of more than $1 million. 

The 22-year-old was ordered to pay almost $295,000 in restitution for his crimes.

“His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities,” Charles Neil Floyd, first assistant attorney for the U.S. District Court for the Western District of Washington, said in a statement. “This sentence must impose real consequences to deter him, and hopefully other would-be hackers.”

Wagenius, who identified himself as “kiberphant0m” and “cyb3rph4nt0m” on online criminal forums, used a hacking tool he helped develop called SSH Brute to steal credentials while on active duty, officials said. Wagenius and his co-conspirators threatened the victim organizations privately and in public forms, officials added.

“It is especially shocking that a member of our armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement.

When federal law enforcement seized Wagenius’ devices in December 2024, they found evidence indicating he had access to thousands of stolen identification documents and large amounts of cryptocurrency. Days later, Wagenius purchased a new laptop against his commanding officer’s order, according to officials, and used it every day over a five-day period in the barracks at Fort Cavazos in Texas with VPN software to hide his identity and location.

The post Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies appeared first on CyberScoop.

Supreme Court permits states to use SAVE database for citizenship checks

By: djohnson
25 September 2026 at 13:41

The U.S. Supreme Court ruled Friday that states may use the federal SAVE database to verify voter citizenship, reversing lower court decisions that found the database was inaccurate and would likely disenfranchise eligible voters.

In its opinion, the majority wrote that “the Federal Government has an obligation to respond to requests from state and local election officials seeking to verify the citizenship of voters.”

“The District Court’s order thus inhibits the Federal Government’s efforts to assist state and local agencies in the proper administration of the midterm elections, the ruling reads. “Under these circumstances, the equities weigh in favor of a stay.”

The Department of Homeland Security initially designed the SAVE database to determine benefit eligibility for immigrants and to track applicants pursuing U.S. citizenship. Under the Trump administration, it had been repurposed to screen voters for citizenship. Critics say the tool is outdated, often inaccurate and poses a significant risk of wrongly removing eligible voters from rolls.

Voting rights groups, including the League of Women Voters and the Electronic Privacy Information Center, filed suit last year. They argued that combining SAVE data with Social Security records violated confidentiality provisions in the Social Security Act, the Privacy Act and the Administrative Procedures Act.

While the ruling permits states to use the database, adoption remains uncertain. Some conservative states have used SAVE previously, saying it has been helpful in maintaining voter rolls. However, most states have resisted the federal government’s efforts to use citizenship verification systems or wrest control of voter registration efforts away from states. The Trump administration has lost 23 federal court cases in attempts to compel states to share additional data.  

Election experts said that the ruling’s impact on 2026 is likely to be limited because of federal laws that bar states from making changes to voter registration within 90 days of an election.

“Given that the SAVE system is used purely as a voluntary system to assist states in keeping their voter lists accurate, states may find this to be a helpful tool to use alongside other mechanisms to keep their lists up to date, even as the Department of Homeland Security itself admits the data is not perfect and evidence suggests the SAVE system has significant flaws,” said David Becker, executive director of the nonprofit Center for Election Innovation and Research.

Three justices – Ketanji Brown Jackson, Sonia Sotomayor and Elena Kagan – dissented, noting that “without full briefing or oral argument, this Court now grants [a stay]—rendering questionable interim rulings about two statutory provisions it has never before interpreted.”

There are laws and procedures that govern how and when federal systems are changed or modified. In this case, DHS did not create a legally mandated system of records notice (SORN) for the SAVE database outlining the broader impacts of the changes on data privacy. Nor did they engage in or offer a public comment period. Instead, they simply announced in May 2025 that the database was ready for use.

In court, the administration cited the Illegal Immigration Reform and Immigrant Responsibility Act to justify merging DHS and Social Security data. That argument was rejected by lower courts, and dissenters argued that the Supreme Court majority overturned those rulings without deliberation about whether the administration’s legal reasoning was sound.

“The majority thus treats [the Illegal Immigration Reform and Immigrant Responsibility Act] as essentially overriding the limits that privacy laws impose on the sharing of citizenship information with DHS. But that ‘back-of-the-napkin assessment,’ is implausible,” wrote Jackson.

The post Supreme Court permits states to use SAVE database for citizenship checks appeared first on CyberScoop.

Yesterday — 25 September 2026Main stream

This Blink video doorbell has dropped to an astonishing AU$27.99 in this early Prime Day deal

Video doorbells used to be fixtures in sci-fi media as futuristic tech, but fast-forward to 2026, almost anyone can install one in their home for not much money or effort, with a lot of the best video doorbells making for an easy home security upgrade.

But if you still find those options a bit pricey, the Blink Video Doorbell System discounted to just AU$27.99 ahead of Amazon’s Prime Big Deal Days sale next week, should certainly make for a no-brainer addition to your home.

This discount matches the Blink Video Doorbell System’s last all-time low price during the last Prime Day sale in July. It’s worth noting, though, that many of the features are locked behind the AU$4.95/m Blink Basic or AU$15/m Blink Plus subscription plans, so those costs should be considered if you want video storage, person detection and more. Amazon is also offering a bundle with two Blink Mini 2K+ cameras for AU$48 or 74% off, perfect for a good starter home security system.View Deal

In our Blink Video Doorbell review, we called it one of the easiest security systems to install, with two different mounting options to suit any household, and setting it up within the Blink mobile app with the included Sync Module Core (which serves as the central system hub) takes just three steps.

Our tester found that it has good image quality at 1440p resolution and 30 frames per second, stable video connection, a wide 150º horizontal field of view and battery life rated for up to two years via three AA lithium batteries.

There’s no included indoor chime, but you can pair this doorbell with a Blink Mini camera that’s sold separately (but you can also buy a bundle with two Blink Mini 2K+ cameras for AU$48) or connect via the Alexa app on your phone to an Amazon Fire Stick or Amazon Echo Show to let you see who’s at your door on your TV or smart display.

As mentioned above, lots of features are locked behind a subscription plan, including video recording, cloud video storage, video sharing, person and vehicle detection, even photo capture. The Blink Basic Plan applies to just one device for AU$4.95 per month or AU$49.95 per year, while Blink Plus lets you add an unlimited number of Blink devices for AU$15 per month or AU$150 per year. For most households, though, the former is a good starting point at a reasonable price, which is made even more enticing by the device’s whopping 72% price drop.

Want to explore your options? Amazon has also discounted more Blink video doorbell models and cameras here.

Cloud and AI bills looking a bit high? Your AI agents may have been let loose and run up huge spending costs

  • One simple prompt could lead to swathes of downstream compute, experts warn
  • Attackers could even exploit your uncontrolled AI to run up costs
  • Greater visibility and circuit breakers are two solutions

Data security company Forcepoint has revealed a major issue with AI agents, but unlike many AI security threats, it doesn't involve stealing data or compromising the model.

Instead, if left to its own devices, Forcepoint says agentic AI could actually consume excessive amounts of compute, tokens, API calls or other resources if sufficient safeguards and limits aren't in place, leading to higher-than-anticipated enterprise cloud bills.

Moreover, the company's research argues that the problem has become more important as AI has become more complex.

Enterprises warned to keep an eye on AI agent compute usage

The result of overwhelmingly complex agentic AI systems is that one single and apparently simply user request could lead to tens or hundreds of downstream operations. Forcepoint labels this as 'unbound consumption'.

Crucially, the analysis found that high compute and token consumption could actually be pretty hard to detect and existing security protocols are unlikely to pick it up, because there doesn't even need to be an attacker for the impacts to take place. All you need is a badly configured automation or a long-running AI session to accidentally lead to runaway costs.

However, Forcepoint worries that attackers can indeed step in to exploit this vulnerability, with malicious users generating huge workloads and consuming massive compute for their own benefit after obtaining an enterprise's credentials, letting them pick up the bill.

Solutions can be as complex as agentic AI itself, but they're now more necessary than ever. Firstly, companies should set budgets at multiple, finer levels, such as API keys, individual users and teams. They should also have greater monitoring powers over where costs are attributed to.

But Forcepoint also calls for agentic circuit breakers to prevent workload and costs from compounding.

"Security teams rarely watch cloud billing dashboards. Finance rarely reviews prompt patterns or agent design," security researcher Jyotika Singh wrote in an urge for enterprises to take the risk more seriously.

Google logo on a black background next to text reading 'Click to follow TechRadar'

We are telling AI chatbots our biggest secrets, but Proton warns our privacy is at huge risk

  • 66% of UK AI users have discussed highly sensitive topics with a chatbot
  • Yet, 64% of respondents are worried that chats will be used to profile them
  • Proton's privacy-first chatbot, Lumo, aims to fix this trust gap

Late at night, when you need to vent about a relationship, ask for career advice, or check a worrying health symptom, who do you turn to? For a rapidly growing number of people, it isn't a friend, family member, or doctor; it's a chatbot.

A new piece of research published today by Proton, the Swiss tech firm behind some of the best VPN services on the market, reveals that a staggering 66% of British AI users have discussed at least one sensitive topic with an artificial intelligence assistant.

However, there is a massive contradiction at the heart of this new digital relationship: we are pouring our hearts out to these chatbots, but we do not actually trust them. According to the survey, 42% of UK users have little or no trust in AI companies to protect their private information, and 11% don't trust them at all.

Despite these glaring privacy reservations, 55% of Brits admit that AI has fundamentally changed their everyday decision-making.

Proton VPN – best for privacy
Based in Switzerland, this privacy-first VPN offers good speeds, advanced anti-censorship features, and a server network that spans 145 countries around the world — including across Africa and Asia, where other providers tend to struggle. While its free VPN plan is handy, it comes with limitations. The good news is that upgrading to a premium subscription will cost you only the equivalent of $2.99 per month.View Deal

The ultimate judgment-free zone

So, why are we sharing our most intimate thoughts with machines we don't trust? The answer is simple: freedom from judgment.

While friends and family remain the preferred choice for most sensitive discussions, AI offers a 24/7 digital confidant that won't react with surprise or embarrassment.

Proton's data shows personal finance is the most commonly discussed sensitive topic (33%), followed closely by work or career problems (32%), mental health struggles (27%), and relationship issues (20%).

66% of people have told an ai chatbot something sensitive.Their finances. Their mental health. Their sex life.At most 1 in 5 trust the companies holding that information.1/6 🧵September 24, 2026

"AI is learning far more about us than a search engine ever could," said Eamonn Maguire, Director of AI Engineering at Proton. "We’re not just asking questions. We’re sharing deeply personal context about our health, finances and relationships. And when technology knows that much about us, privacy can't be an afterthought."

The primary worry isn't just about the AI remembering a single chat, or even the risk of human reviewers reading your logs. Users are increasingly terrified of the bigger picture.

In the UK, 64% of respondents are concerned that their vulnerable conversations are being weaponized to build detailed advertising or marketing profiles. Meanwhile, 52% are worried their secrets are being fed back into the machine to train future AI models.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

How Lumo promises a private alternative

Lumo AI by ProtonVPN

(Image credit: Lumo/Edited with Gemini)

Despite these valid fears, Brits are highly receptive to a more secure way forward. A massive 82% of users said they would be more likely to use an AI chatbot specifically designed around privacy, and 44% would be far more willing to share sensitive information if they were given a cast-iron guarantee that their chats wouldn't be used for AI training.

This is exactly where Proton hopes to fill the gap with Lumo. Built with the same end-to-end encryption ethos as the company's famous email client, Lumo is an open-source, privacy-first ChatGPT alternative.

To help users understand the scale of their digital footprint, Proton recently launched AI Paper Trail, a tool from Lumo that visually demonstrates exactly how much personal information an average AI conversation leaks about a user's inner life.

"People have already decided that AI is useful enough to hear their money worries, doubts and everyday concerns. They are handing AI companies their inner lives and biggest secrets on the assumption that they will protect them when it's actually the opposite. AI's business model depends on learning from them" Maguire added.

❌
❌