Reading view

There are new articles available, click to refresh the page.

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise 

Security teams are being asked to defend a growing attack surface with fewer people and around the clock, against threat actors who never take a night off. As cyberattackers increasingly use AI to launch and scale campaigns, the volume, speed, and sophistication of threats continue to rise. Closing that gap takes more than tooling. It takes a partner that pairs a leading security platform with scaled intelligence and human experts who can act on your behalf at any hour. That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026). Read the excerpt here.

Expert-led MDR, built on the Microsoft Defender platform

Microsoft Defender Experts MDR is a round-the-clock, expert-led managed detection and response service that helps security teams triage, investigate, and respond to incidents so they can stop cyberattackers in their tracks and prevent future compromise. Rather than bolting a separate stack of tools and connectors onto your environment, the service operates natively on Microsoft Defender, with built-in protection across endpoints, identities, email, cloud apps, cloud workloads, and network security, as well as around-the-clock proactive threat hunting with Microsoft Defender Experts Hunting.

Because the service is delivered on the same platform it monitors, detection and intelligence improvements reach customers continuously. The insights our experts generate also strengthen protection across the broader Defender ecosystem, so every customer benefits from what we learn defending the next environment.

Graphic showing Microsoft as a Leader in the IDC Marketscape.
The IDC MarketScape vendor assessment model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market. The research uses a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each supplier’s position within a given market. The Capabilities axis measures supplier product, go-to-market, and business execution in the short term, while the Strategy axis measures how well a supplier’s strategy aligns with customer requirements over a 3-5-year timeframe. Supplier market share is represented by the size of the icons.

Threat intelligence at internet scale

Great detection starts with great intelligence. Defender Experts MDR draws on Microsoft’s global threat intelligence: more than 10,000 security researchers and 100 trillion signals analyzed every day across billions of users and millions of organizations.1 That breadth lets our analysts recognize subtle patterns early, often before a campaign escalates, and respond with higher-confidence attribution than intelligence sourced from any single customer’s telemetry could provide.

AI-accelerated operations, expert-led decisions

Defender Experts MDR also combines advanced AI and generative AI with seasoned human experts. AI filters noise, grades and classifies incidents, and accelerates investigation at machine speed and scale, while our analysts own the outcome. According to the IDC MarketScape, “70% AI-assisted workflows are enabled through automated noise filtering, AI-based grading, and agentic operations while maintaining expert decision-making.” Furthermore, “quantified outcomes noted include 97% AI classification accuracy, 77% malware/phishing agent-investigated, 72% faster resolution combining AI and humans, and 45% autonomous investigations.”

The impact shows up in the work. Over the past year, Defender Experts mitigated 27,000 high-severity incidents, and the team’s threat research now contributes a meaningful share of all Defender detections, enriching protection for customers well beyond the MDR service itself. Throughout, a dedicated security delivery expert and on-demand access to our experts keep customers informed with proactive check-ins, live dashboards, and clear, actionable reporting.

Managed threat hunting, included

Many providers treat proactive threat hunting as a premium add-on. Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment. These hunts are informed by Microsoft Threat Intelligence, Defender telemetry, and human analysis, in order to better identify malicious activity and improve security operations center (SOC) response.

When a threat is found, Defender Expert notifications appear as incidents in the Defender portal with technical context, recommended remediation, and, when needed, access to on-demand support for additional guidance. The work also feeds back into hunter-trained AI and reporting, so customers can see what was investigated, how the activity maps to MITRE tactics, and how threats are categorized by behavior, characteristics, and impact.

Get started

Read the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, drive SOC efficiency, and help you stay ahead of emerging cyberthreats.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters, and follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.


1Microsoft Digital Defense Report 2025.

The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise  appeared first on Microsoft Security Blog.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

First observed in July 2025, DeadLock operators employ double extortion tactics, encrypting victim environments while threatening to publicly release exfiltrated data. As of July 2026, the operators have published more than 80 compromised organizations on their data leak site, called the DeadLock blog, with more than half of the claimed victims in Europe. Microsoft identified DeadLock ransomware impacting organizations across information technology (IT), mining, transportation and logistics, manufacturing, hospitality, consumer goods, and other sectors in Europe, Asia, North America, South America, and Africa.

The DeadLock encryptor includes a resource-aware throttling mechanism designed to maintain system responsiveness during encryption. In addition to its encryption capabilities, the ransomware also appears to implement language or country-based geofencing designed to avoid running in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries, a pattern commonly observed among ransomware operators believed to operate from those regions. Together, these capabilities demonstrate how DeadLock combines established ransomware tradecraft with decentralized infrastructure designed to improve operational resilience.

In this blog, we present a technical analysis of the DeadLock ransomware encryptor, covering its execution flow, defense evasion techniques, encryption design, and post-encryption behaviors, including a decentralized recovery chat system. We also provide indicators of compromise (IOCs), Microsoft Defender detections, and mitigation guidance to help organizations defend against this threat and similar ransomware activity.

Pre-encryption

Configuration parsing

Before performing any malicious activity, the DeadLock encryptor decrypts an embedded configuration blob using XOR decoding with an 8-byte key.

Below are the malware’s configuration fields and their values.

FieldValue
Victim UID<redacted>
Malware public key03bf50bbf97c4e951e66ff12b689a37a3ce675b4921e254eae76da77573843e4a9
Encryption rule1000,05052429880,025124288000,010524288000,F991114288000
Language exclude listGeofencing language IDs (see Language geofencing)
Process stop listProcesses to terminate (see Process and service termination)
Service stop listServices to stop and delete (see Process and service termination)
File exclude listExtensions and file names to avoid encrypting (see Directory traversal)
Directory exclude listPre-traversal filter with directories to avoid encrypting (see Directory traversal)
Sub-path Exclude ListSub-paths to avoid encrypting during traversal (see Directory traversal)
Text ransom noteFull text ransom note content (see Ransom notes deployment)
HTML recovery chatFull HTML/JS interactive chat page (see Recovery chat: Technical architecture)

Language geofencing

As an early exit check, the malware queries the system’s default and user interface (UI) languages. If either language matches the exclude list in the configuration, the malware self-deletes immediately without performing any encryption.

The following languages trigger this exit behavior:

LANGIDLanguageCountry
1049RussianRussia
1058UkrainianUkraine
1059BelarusianBelarus
1064Tajik (Cyrillic)Tajikistan
1065PersianIran
1067ArmenianArmenia
1068Azeri (Latin)Azerbaijan
1079GeorgianGeorgia
1087KazakhKazakhstan
1088KyrgyzKyrgyzstan
1090TurkmenTurkmenistan
1114SyriacSyria
2072Romanian (Moldova)Moldova
2092Azeri (Cyrillic)Azerbaijan
2115Uzbek (Cyrillic)Uzbekistan
8193ArabicOman
9217Arabic (Yemen)Yemen

Command-line processing and privilege elevation

The encryptor’s behavior branches based on command-line arguments and the current privilege level. If a target directory path is provided as the command-line argument, the malware skips all preparation steps and jumps directly to encryption. This feature allows the operator to invoke the encryptor with specific targets for focused encryption. If no sub-commands are provided and the process is already elevated, the malware proceeds normally through all execution phases.

The more interesting case occurs when no command-line argument is provided while the process is not elevated. In this scenario, the malware attempts to gain administrator privileges through a batch-script-based elevation technique. It generates a randomly named .cmd file (8 uppercase characters, such as ESYEKQSY.cmd) and executes it using ShellExecuteW with the RunAs verb, which triggers the Windows User Account Control (UAC) consent dialog. If the user denies the prompt, the malware retries up to 10 times before giving up and exiting.

During dynamic analysis, the sample did not successfully relaunch itself with elevated privileges. As a result, full pre-encryption preparation appears to require execution from an already elevated context. When invoked with a target path, the malware bypasses preparation and proceeds directly to encrypt accessible files. This behavior is specific to the analyzed sample and may change in later variants.

Token privilege escalation

When running with administrator privileges, the malware further expands its access by enabling SeDebugPrivilege, SeRestorePrivilege, SeBackupPrivilege, SeTakeOwnershipPrivilege, SeAuditPrivilege, and SeSecurityPrivilege. These privileges increase the malware’s ability to interact with system processes, protected files, and security-related settings, helping it overcome common access restrictions and maximize the scope of files and resources it can target during the encryption phase.

Recycle bin emptying

The malware silently empties the recycle bin on all drives without any UI or confirmation dialog, eliminating a potential source of file recovery for victims.

Custom icon registration

To visually brand encrypted files, the malware writes an embedded .ico file to C:\ProgramData\<UID>.ico and registers it as the default icon for files with the extension .dlock.

To associate the custom icon with encrypted files, the ransomware creates the HKLM\SOFTWARE\Classes\.dlock\DefaultIcon registry key and sets its (Default) value to the path of the dropped icon file.

Below is the malware’s embedded .ico file.

A lock symbol surrounded by a circular target.
Figure 1. DeadLock icon for encrypted files

Process and service termination

Before starting encryption, the malware terminates processes and disables services that could interfere with file access or provide defensive capabilities. This approach ensures that locked files become accessible for encryption while simultaneously disrupting the environment’s ability to detect, respond to, or recover from the attack.

For services, the malware enumerates all active Win32 services and compares them against the stop list in the configuration. For each matching service, DeadLock sets its start type to DISABLED and sends a stop command to terminate that service. Notable targets include windefend (Windows Defender), vss/swprv/wbengine (Volume Shadow Copy and Backup services), mssearch, Hyper-V services (vmcompute, vmms), and Active Directory services (adws, ntds, kdc). Below is the full service stop list in the malware configuration:

A list of service names and their corresponding service types, primarily related to Windows services.
Figure 2. Service stop list

For processes, the malware enumerates all running processes and terminates any matching its stop list while skipping its own process ID. Targeted processes include security tools (msmpeng, securityhealthservice, smartscreen), backup and cloud sync applications (onedrive, dropbox, googledrivefs, owncloud), remote access tools (anydesk, putty, mstsc, rustdesk), shell and system processes (explorer, powershell, taskmgr, cmd), and search/indexing services. Below is the full process stop list in the malware configuration:

A list of various Windows processes and system components.
Figure 3. Process stop list

Event log clearing

To eliminate forensic evidence, the malware employs three complementary methods that collectively ensure every event log channel on the system is cleared of existing entries, disabled from recording future events, and has its access permissions locked down:

  • Direct clearing: Clears the following log channels via the classic Event Log API: Application, Security, Setup, Servicing, Eventlog, Forwarded Events, Windows PowerShell, and System.
  • Registry-based disabling: Enumerates every sub-key under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels. For each channel, sets Enabled to 0 (disabling all future logging) and overwrites ChannelAccess with a restrictive Security Descriptor Definition Language (SDDL) string that limits access to SYSTEM, built-in administrators, and local admin.
  • Modern API enumeration: Uses wevtapi.dll to enumerate all registered event log channel paths (including custom application channels not in the hardcoded list) before clearing each one.

By combining API-based clearing, registry manipulation, and full channel enumeration, the malware covers multiple log sources, including third-party application logs and custom diagnostic channels, to minimize existing forensic evidence on the infected device.

Directory traversal

To maintain system stability and ensure the victim can access ransom instructions, the malware excludes specific directories, file extensions, and file names from encryption. This selective encryption model is a common ransomware design pattern where the system must remain operational enough for the victim to receive instructions and facilitate payment.

Extensions and file names from the configuration’s file exclude list are skipped during encryption:

A list of file extensions and system files related to Windows operating system.
Figure 4. List of skipped extensions and file names

For directory processing, the malware uses a two-tier directory exclusion system applied at different stages of the encryption pipeline. Tier 1 provides rough filtering that saves significant time by avoiding traversal overhead, while tier 2 provides granular path-specific exclusions within directories that are traversed. Both prevent encryption, but they operate at different stages of the traversal pipeline.

In its pre-traversal phase (tier 1), the malware checked at the drive batch level before threads are spawned for traversal. If a top-level directory matches against the configured directory exclude list (\users\*\appdata, program files (x86)\, program files\, and programdata\), the entire tree is skipped without being walked.

In its during-traversal phase (tier 2), the malware checked the file name during recursive directory enumeration and applied to both subdirectories and files as they are encountered. In this tier, the directory and file names are checked against the configured sub-path exclude list below.

A list of file paths and folders typically associated with the Windows operating system.
Figure 5. Sub-path exclude list

Encryption

Resource-aware throttling

One of the more distinctive aspects of the DeadLock encryptor is its resource-aware throttling mechanism, designed to keep the infected system responsive during encryption. The malware spawns a dedicated monitoring/dispatch thread per drive batch that acts as a gatekeeper for file encryption dispatch. Before dispatching each new file to be encrypted, this thread polls system resource utilization and checks against hardcoded thresholds:

  1. Polls memory and CPU idle before each file dispatch
  2. Calculates memory usage percentage and CPU idle percentage
  3. If memory usage exceeds 29% or CPU load exceeds 70% (idle < 30%), the dispatch thread pauses via a waitable timer and retries until resources return below thresholds
  4. Once thresholds are within limits, atomically sets a dispatch flag on the work queue and signals waiting encrypting worker threads

With this mechanism, worker threads already encrypting files are not interrupted, and only the dispatch of new files is gated. This means partially encrypted files are expected to complete, and the throttling manifests as reduced parallelism rather than stop/start behavior. This approach can prevent system hangs that would alert the user and reduce the likelihood of behavioral detection by maintaining normal-looking resource consumption patterns.

Thread architecture

For the encryption work itself, the malware spawns directory processing threads, with the thread count being 2 times the CPU core number. Each thread recursively traverses directories, dropping ransom notes and dispatching files for encryption. Individual file encryption threads are tasked with handling the actual cryptographic operations.

Cryptographic scheme

The DeadLock ransomware implements a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher for file encryption. Key encapsulation uses the Networking and Cryptography Library (NaCl) crypto_box construction, which pairs an asymmetric key exchange with authenticated encryption to securely wrap each file’s symmetric key.

LayerAlgorithmPurpose
File content encryptionXChaCha20Symmetric stream cipher
Key encapsulationCurve25519 Elliptic Curve Diffie-Hellman (ECDH) + XSalsa20-Poly1305Asymmetric key wrapping (NaCl crypto_box)
Random generationWindows CryptoAPIAll key material random generation


The configuration’s operator public key 03bf50bbf97c4e951e66ff12b689a37a3ce675b4921e254eae76da77573843e4a9 is 33 bytes. The leading 03 byte is a SEC1 compressed point format prefix borrowed from Bitcoin/secp256k1. The malware validates this prefix byte against a lookup table that accepts 00, 02, 03, 04, and 05, mapping each to an expected key length.

After format validation, only the remaining 32 bytes are used in the actual Curve25519 ECDH scalar multiplication. This SEC1 prefix is non-standard for Curve25519, which natively uses bare 32-byte keys, and the malware author has likely adopted it for format versioning across their builder and decryptor tooling.

Per-file encryption process

For each target file, the malware performs the following sequence of operations:

  1. Rename the target file from <filename> to <filename>.<UID>.dlock
  2. Open the renamed file and retrieve file size/attributes
  3. Clear the system attribute if FILE_ATTRIBUTE_SYSTEM is set
  4. Determine the encryption strategy based on file size (see File size-based encryption strategy)
  5. Generate cryptographic material:
  6. 32-byte random XChaCha20 key
  7. 24-byte random XChaCha20 nonce (first 16 bytes for HChaCha20 subkey derivation, last 8 bytes as stream nonce)
  8. 32-byte random ephemeral Curve25519 private key
  9. 12-byte random file tag (only the first byte is functionally referenced by the encryptor to derive padding length; the remaining 11 bytes serve as a random file identifier written to the cleartext footer, likely used by the decryptor for file correlation/tracking)
  10. 1–10 bytes random padding (length = file_tag[0] % 10 + 1)
  11. Perform Curve25519 ECDH: Multiply the ephemeral private key by the attacker’s embedded public key to derive a shared secret
  12. Build metadata plaintext: XChaCha20 key + 24-byte XChaCha20 nonce + random padding + dDlK magic + optional FA flag + chunk parameters
  13. Encrypt metadata using crypto_box (XSalsa20-Poly1305) with the ECDH shared secret and a zero nonce
  14. Encrypt file content using XChaCha20 with the generated key and 24-byte nonce
  15. Append the encrypted footer/metadata to the end of the file

The use of a zero crypto_box nonce is worth noting. This is cryptographically safe because each file generates a unique ephemeral Curve25519 keypair, which produces a unique ECDH shared secret per file. With this, a constant zero nonce never repeats with the same key.

The entire design ensures that each file is encrypted with a distinct key derived from a per-file ephemeral key exchange, eliminating any possibility of key reuse across files. Overall, the cryptographic construction is sound and does not present a practical path to decryption without the attacker’s private key.

File size-based encryption strategy

To balance encryption thoroughness with speed, the malware implements a tiered encryption policy based on file size. The encryption rule in the configuration 1000,05052429880,025124288000,010524288000,F991114288000 encodes this policy. Each comma-separated entry is parsed by splitting at position 3: the first 3 characters represent the encryption percentage (decimal), and the remaining characters represent the file size threshold (decimal bytes). The special prefix F replaces the percentage field with a chunked-full mode.

RuleEncryption percentFile size thresholdBehavior
1000100%≥ 0 bytesDefault: encrypt entire file
0505242988050%≥ ~50 MBEncrypt 50% of file in distributed chunks
02512428800025%≥ ~118 MBEncrypt 25% in distributed chunks
01052428800010%≥ ~500 MBEncrypt 10% in distributed chunks
F991114288000Chunked≥ ~1 GBSpecial full-chunk mode with calculated intervals


Rules are evaluated in order, and the last matching rule wins. For example, when the malware processes a 2 GB file, all rules match, but the final F99… entry will determine the encryption behavior.

For partial encryption, the malware calculates:

  • Total bytes to encrypt = ceil(file_size × (percentage / 100))
  • Encrypted block count = ceil(total_bytes_to_encrypt / 512)
  • Skip interval = floor((file_size − total_bytes_to_encrypt) / encrypted_block_count)

This creates an intermittent encryption pattern where 512-byte blocks are encrypted at regular intervals throughout the file. The result is a file that is rendered unusable while requiring only a fraction of the time needed for full encryption. This is a crucial optimization for the ransomware when targeting large files such as databases, virtual machine images, and backups.

File footer

After encryption, the malware appends a structured metadata blob to the end of each file. This footer contains all the information the decryptor needs to reverse the encryption, along with markers for format validation:

A detailed structure of a cryptographic message, including encryption, authentication, and various data types arranged in a hierarchical format.
Figure 6. DeadLock file footer

The footer serves several important functions:

Key and nonce reconstruction: The cleartext ephemeral Curve25519 public key (33 bytes) at the end of the footer allows the decryptor to recompute the ECDH shared secret and open the crypto_box to recover the XChaCha20 key and nonce used for file content encryption.

Inner dDlK magic (decryption validation): After the decryptor opens the crypto_box, it checks for the dDlK marker at the expected offset (32 + 24 + padding_length bytes into the plaintext) to confirm the correct private key was used and that decryption succeeded. While the Poly1305 Message Authentication Code (MAC) already provides cryptographic integrity verification, this marker offers a fast format-level sanity check.

FA flag (decryption mode indicator): This flag is used by the decryptor to determine which read strategy to use when reversing the encryption. It is present when the file was encrypted using sequential/contiguous block encryption, and absent when intermittent/skip encryption was used. Specifically, FA is appended in two cases:

  1. F-prefix rule matched: When the file size triggers the F991114288000 config entry (the special chunked-full mode), the FA flag is always set.
  2. Percentage rule with zero skip interval: When a percentage-based rule matches but the calculated skip interval between encrypted chunks works out to zero (meaning the percentage effectively covers the entire file), FA is also set.

Without this flag, the 8-byte chunk parameters in the footer would be ambiguous as they could represent either a block count or a skip interval. The FA flag resolves this ambiguity and enables the decryptor to correctly reconstruct the original file.

File identifier/format tag: The 12-byte random value in the cleartext footer serves as a file identifier (with the first byte used to derive the padding length inside the encrypted payload).

Post-encryption

Wallpaper

As an immediate visual indicator of compromise, the malware generates a custom BMP wallpaper file at runtime using the victim’s screen resolution. Below is an example of the generated BMP wallpaper:

DeadLock wallpaper stating the infrastructure is DeadLocked with a note to open the file HOW_RECOVER .< UID>.txt for instructions to recover.
Figure 7. DeadLock wallpaper

The wallpaper is written to C:\ProgramData\<UID>.bmp (on Vista and later) or C:\Documents and Settings\All Users\Application Data\<UID>.bmp (on XP), set as the desktop background, and persisted in the registry at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Wallpaper.

Ransom notes deployment

After encrypting files, the malware deploys two types of ransom notes, each with distinct deployment logic and purpose:

Text note (HOW_RECOVER.<UID>.txt): The text note is dropped into every encrypted directory, but with a notable timing behavior: it is only deployed during the second pass of the directory processing loop. The malware iterates over drive batches multiple times, and the text note drop is gated by an iteration counter. On the first pass, the text note is suppressed, likely to prioritize encryption speed before littering the file system with ransom note files. For defenders and analysts, this has a practical implication: if testing with a minimal drive configuration that only triggers a single iteration, the text note will never appear.

Below is the text note content from the malware’s configuration.

A ransom note from a cybercriminal demanding payment to decrypt stolen data and provide a security report.
Figure 8. DeadLock text ransom note

HTML note (RECOVERY_CHAT.<UID>.html): This file is dropped to all drive root directories and all Desktop folders. Unlike the text note, the HTML note is a full interactive web application with a self-contained single-page application that implements end-to-end encrypted chat, a paginated data leak blog, and a file browser, all without requiring a traditional backend server. The technical architecture of this recovery chat system is detailed in Recovery chat: Technical architecture.

Recovery chat: Technical architecture

The most distinctive feature of the DeadLock ransomware is its recovery chat system. The RECOVERY_CHAT.<UID>.html file is a self-contained HTML application that implements a full end-to-end encrypted chat system, a paginated data leak blog, and a file browser, all without requiring a traditional backend server.

DeadLock About page telling the victim that all their important files are encrypted by the ransomware, including documents, photos, videos, databases, and other critical data. It tells the victim to contact the operators to receive a decryption key or else the data will be leaked and published on the DeadLock blog.
Figure 9. HTML application “About” page UI

The architecture is designed with three decentralized components.

Polygon blockchain as configuration store

Rather than relying on traditional domain-based infrastructure that can be seized or taken offline, the DeadLock operators store configuration data on the Polygon blockchain. Two smart contracts serve as censorship-resistant infrastructure:

ContractAddressFunction selectorPurpose
Chat proxy0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe0x933a9ce8Stores the proxy server URL
Blog0x757984507c82c8dA1d3969c535dB5706eEE6426C0xd4070542Stores actor’s blog posts


The HTML page issues eth_call requests to public Polygon Remote Procedure Call (RPC) endpoints (no wallet required with read-only calls) to obtain the proxy server address. The blog contract takes offset and limit parameters (for pagination) and returns structured data including post titles, bodies, timestamps, image URLs, and file attachment links.

On-chain storage provides several strategic advantages for the threat actor: the proxy URL can be updated by modifying the smart contract without changing any victim-facing infrastructure, and no domain registration or DNS infrastructure is required. This represents a notable evolution in ransomware infrastructure design.

The HTML recovery chat cycles through six public RPC endpoints for redundancy: polygon-bor-rpc.publicnode[.]com, polygon.drpc[.]org, polygon-pokt.nodies[.]app, polygon-rpc[.]com, 1rpc[.]io/matic, and polygon.meowrpc[.]com.

Session network for end-to-end encrypted chat

For victim-operator communication, chat messages are routed through the Session decentralized messenger network, which is an onion-routed, swarm-based messaging protocol that provides anonymity for both parties. The proxy server (whose URL is retrieved from the blockchain) acts as a relay between the victim’s browser and Session swarm nodes.

DeadLock Chat page with instructions for the victim to create a username and password to communicate with the operators.
Figure 10. HTML application ”Chat” page UI

Key generation: DeadLock’s design choice is that the victim’s Session identity is derived deterministically from their sign-in credentials. When the victim enters their credentials on the HTML page, the following derivation occurs:

A sequence of steps in cryptographic key generation, including hashing a seed, generating an Ed25519 keypair, converting it to Curve25519 format, and forming a session address.
Figure 11. Derivation after victim entered credentials

This deterministic derivation means the same credentials always produce the same keypair, and no account registration is needed as the victim’s Session identity exists only when they enter the correct credentials. If the victim forgets their credentials, the identity is unrecoverable (as stated by the actor in the chat UI). The 05 prefix is Session’s standard network identifier for user accounts.

Sending a message: The following sequence occurs when a message is sent:

  1. Encode the body and timestamp as protobuf
  2. Create an actor message and a self-sync copy
  3. Pad plaintext to 160-byte boundary
  4. Sign the padded content and key context with Ed25519
  5. Append the sender public key and signature
  6. Seal each payload with the recipient’s Curve25519 key
  7. Wrap in Session’s onion request protobuf format (verb: PUT, path: /api/v1/message)
  8. Ask the proxy to submit both copies to their respective swarms

Receiving a message: The following sequence occurs when a message is received:

  1. Sign “retrieve” + timestamp with the victim’s Ed25519 key
  2. Select a node associated with the victim’s own swarm
  3. Ask the proxy to poll for messages addressed to that identity
  4. Open each sealed box with the victim’s Curve25519 keypair
  5. Remove the appended public key and signature
  6. Strip padding, decode protobuf, and extract the message body

Data leak blog and Wasabi file hosting

The recovery chat page also provides access to a data leak blog whose content is stored on the Polygon blockchain.

DeadLock Blog page displaying redacted, leaked files published on the DeadLock blog.
Figure 12. Redacted HTML app “Blog” page UI

Blog posts retrieved from the smart contract support BBCode formatting, image galleries, and file attachments using either direct URLs or Wasabi protocol links that open an in-browser file explorer. The HTML application contains a full Amazon Web Services (AWS) S3-compatible file browser that parses the Wasabi credentials from the URI, generates AWS4-HMAC-SHA256 signed requests, lists bucket contents with folder navigation, and generates pre-signed download URLs for individual files. This allows the attacker to host stolen data on Wasabi and provide victims or the public with browsable access to the leaked files without running a web server.

Infrastructure resilience summary

HTML recovery chat infrastructure showing how the Polygon RPC communicates with Smart contracts, Proxy server communicates with Session network, and Wasabi S3 with file browser.
Figure 13. HTML recovery chat infrastructure summary

The architecture is significantly more resilient to takedown and censorship efforts, but it is not independent of off-chain infrastructure:

  • Proxy replacement: The actor can update the on-chain proxy URL without changing the HTML
  • On-chain persistence: Contract-stored blog data is resistant to conventional hosting takedowns
  • RPC dependency: The page still requires access to at least one public Polygon RPC endpoint
  • Proxy dependency: Chat access depends on the current custom proxy remaining reachable
  • Storage dependency: Images and leaked files can be removed from CDN or Wasabi hosting
  • Session resilience: Distributed swarm storage reduces reliance on a single messaging server

This infrastructure model represents a meaningful evolution from traditional ransomware communication channels and poses new challenges for takedown efforts.

Self-deletion

As a final cleanup step after encryption completes, the malware creates a batch to delete its own binary from disk. The cleanup batch loops until it successfully deletes the malware binary, then removes itself:

Self deleting batch loop script
Figure 14. Self-deleting batch loop

Defending against DeadLock ransomware

Microsoft recommends the following mitigations to reduce the impact of this threat.

  • Read the human-operated ransomware threat overview for advice on developing a holistic security posture to prevent ransomware, including credential hygiene and hardening recommendations. 
  • Turn on cloud-delivered protection in Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attacker tools and techniques. Cloud-based machine learning protections block a huge majority of new and unknown variants. 
  • Run endpoint detection and response (EDR) in block mode so that Microsoft Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach. 
  • Turn on tamper protection features to prevent attackers from stopping security services. In addition to tamper protection, you can also enable and configure Microsoft Defender Antivirus always-on protection in Group Policy
  • Configure investigation and remediation in full automated mode to let Microsoft Defender for Endpoint take immediate action on alerts to resolve breaches, significantly reducing alert volume. 
  • Configure automatic attack disruption in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully. 
  • To help preserve existing systems in the event of a ransomware attack, configure a Controlled Folder Access (CFA) policy to be as strict as possible. CFA protects valuable data from threats like ransomware by preventing write access to common system folders; more folders can also be added. Establishing this policy ahead of a ransomware event can enable organizations to respond quickly to ransomware signals, deploying the CFA policy to limit the destructive impact of an active attack. In certain instances, a CFA policy can also be leveraged proactively on specific sensitive assets that will not be negatively impacted by restrictive protections. Use audit mode to evaluate the impact to your organization in these cases. 
  • Microsoft Defender XDR customers can turn on attack surface reduction rules to prevent several of the infection vectors of this threat. These rules, which can be configured by any user, offer significant hardening against targeted attacks. In observed attacks, Microsoft customers who had the following rules turned on could mitigate the attack in the initial stages and prevent hands-on-keyboard activity:  

You can assess how an attack surface reduction rule might impact your network by opening the security recommendation for that rule in Vulnerability management. In the Recommendation details pane, check the user impact to determine what percentage of your devices can accept a new policy enabling the rule in blocking mode without adverse impact to user productivity.   

Microsoft Defender detections

Microsoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.

Microsoft Defender Antivirus

Microsoft Defender Antivirus detects threat components as the following malware:

Microsoft Defender for Endpoint

The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.

  • Ransomware-linked threat actor detected
  • Ransomware behavior detected in the file system
  • Possible ransomware activity
  • File backups were deleted
  • Potential human-operated malicious activity
  • Possible data exfiltration
  • Suspicious wallpaper change

The following alerts might indicate threat activity associated with DeadLock ransomware if Defender for Endpoint is set to block mode.

  • ‘DeadLock’ ransomware was detected
  • ‘DeadLock’ ransomware was prevented

Microsoft Defender for Cloud Apps

The following alert might indicate threat activity associated with this threat. This alert, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.

  • Ransomware activity

Microsoft Security Copilot

Microsoft Security Copilot is embedded in Microsoft Defender and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.

Customers can also deploy AI agents, including the following Microsoft Security Copilot agents, to perform security tasks efficiently:

Security Copilot is also available as a standalone experience where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers developer scenarios that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.

Threat intelligence reports

Microsoft Defender XDR customers can use the following threat analytics reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.

Microsoft Security Copilot customers can also use the Microsoft Security Copilot integration in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this threat actor.

Indicators of compromise

IndicatorTypeDescription
a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4SHA-256DeadLock ransomware encryptor
deadlock.liveblog365[.]comURLLeak site domain
dlock.liveblog365[.]comURLLeak site domain
deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onionURLLeak site domain
deadlockblog.great-site[.]netURLLeak site domain
deadlockblog.medianewsonline[.]comURLLeak site domain

Learn more

For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.

The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

As organizations adopt AI, they must secure both cloud and AI environments through a unified security control plane as their attack surface expands. Because modern applications and AI workloads are built and run in the cloud, security teams must understand which exposures matter most, prioritize what can truly be exploited, and reduce risk across cloud infrastructure, applications, identities, data, and AI systems in one place. 

Modern IT estates now span multiple clouds and on-premises systems, with architectures built on containers, Kubernetes, serverless functions, microservices, APIs, and AI-powered workloads. This increases both the volume and the interconnectedness of security signals. The challenge is no longer identifying individual risks, but determining how misconfigurations, identities, and data exposures combine to create real attack paths, and which of these are most critical to fix at the source. 

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift. The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

Within this evolving market, KuppingerCole names Microsoft a Leader across all four of its Leadership categories: Overall, Product, Innovation, and Market. In the report’s words: 

“Microsoft earns its Overall Leadership with its Defender for Cloud that is redefining the CNAPP market by extending cloud security beyond infrastructure protection and into a unified security platform for cloud, data, identity, AI, and security operations, supported by one of the industry’s most advanced agentic AI ecosystems.” 

Graphic of the KuppingerCole Leadership Compass showing Microsoft in the under right quadrant to indicate it is an overall leader.

That recognition reflects where the category is heading: toward platforms that unify cloud and AI security into one operational view of risk. 

Why CNAPP is being redefined 

KuppingerCole makes a clear point: CNAPP is no longer about posture or visibility alone. It is becoming the operational foundation for securing AI-powered applications, services, and business processes, across the full software lifecycle from cloud infrastructure to the AI systems running on top of it.

Modern environments introduce complexity across: 

  • Multicloud and hybrid infrastructure. 
  • Rapid development and continuous deployment. 
  • Containers, serverless, microservices, and APIs. 
  • AI models, agents, pipelines, and machine identities. 

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console. Organizations now need platforms that can: 

  • Correlate posture, runtime, identity, data, application, and AI signals. 
  • Prioritize risk based on exploitability, not severity alone. 
  • Integrate security across development, cloud operations, and the SOC. 
  • Bring AI systems into the same risk model as the rest of the cloud. 

Runtime intelligence is now central to this shift. Across the platforms KuppingerCole evaluated, 94% detect active exploitation of the complex attack paths they surface, moving teams from long lists of findings to the exposures threat actors can actually use. 

What distinguishes leading platforms 

KuppingerCole evaluates providers on product strength, innovation, and market presence, and, more importantly, on how effectively they help organizations manage real risk across cloud and AI. Several themes define the next generation of platforms: 

  • AI security posture management that governs models, pipelines, and AI-specific attack paths. 
  • Agentic AI that investigates, validates exposures, and helps remediate, not just detect. 
  • Runtime-driven risk prioritization focused on what is exploitable in production. 
  • Security graphs and attack path analysis across identity, data, network, workload, and AI. 
  • Convergence of CNAPP with cloud detection and response, integrated with the SOC. 

Taken together, these capabilities represent a move from fragmented visibility to connected, contextual risk management that spans cloud and AI in a single fabric. 

How Microsoft helps organizations manage real risk 

1. Connect cross-domain signals to prioritize real attack paths 

Most security tools surface large volumes of findings, but isolated findings do not reflect how cyberattacks actually happen. Microsoft Defender for Cloud uses the Cloud Security Graph and risk-based, multicloud attack path analysis to correlate posture, identity (human and non-human), data, network, and workload signals and identify which risks are truly exploitable. A misconfigured storage resource may look low priority on its own. Exposed to the internet, combined with excessive permissions, and connected to sensitive data, it becomes part of a clear attack path.  

What this means: Security teams can prioritize real attack paths instead of individual findings, helping reduce alert fatigue and improve remediation speed and precision.  

2. Secure AI as part of cloud risk, and use AI to run security 

Defender for Cloud brings AI security posture management into the same model as the rest of the cloud, helping organizations validate AI deployment configurations, access controls, model provenance, approved model usage, and identify potential shadow AI risks within supported environments. Through Microsoft Security Copilot and a growing set of specialized security agents, the platform also helps teams investigate, prioritize, guide remediation, and automate workflows.  

What this means: Organizations can govern AI as part of cloud risk rather than in a separate silo, and shift AI from flagging risk to actively helping resolve it. 

3. Reduce complexity from code to cloud to SOC 

As environments scale, fragmented tools make it difficult to understand how risks connect and where to focus first. Defender for Cloud connects code and infrastructure definitions, assesses cloud configurations, protect workloads at runtime, monitor applications and APIs, govern identities, correlate threats across the broader digital estate, and use AI to accelerate investigation and remediation across multicloud and hybrid environments. 

What this means: Security teams can investigate faster, prioritize more consistently, and respond more quickly across fragmented cloud and application environments. 

What this signals for security leaders 

The Leadership Compass offers a signal for where cloud security is headed: toward platforms that connect context across cloud, application, and AI environments so teams can prioritize the risks most likely to be exploited and reduce exposure faster. Security leaders should now ask: 

  • Can the platform correlate signals across identity, endpoints, data, cloud, runtime, and applications? 
  • Does it see AI models, agents, and pipelines as part of cloud risk, or is AI a separate tool? 
  • Can it prioritize risk based on exploitability, not just severity? 
  • Does AI help the team investigate and remediate, or only detect? 
  • Can it scale across multicloud and AI environments and reach into the SOC? 

These are the capabilities that define the next generation of cloud-native application protection. 

Bottom line 

KuppingerCole’s 2026 CNAPP Leadership Compass reinforces a clear shift: CNAPP is becoming the control plane for managing risk across cloud, identity, data, applications, and AI. Microsoft’s recognition as a Leader across all four Leadership categories reflects this shift, bringing posture, runtime, identity, data, application, and AI signals into a connected platform that helps organizations prioritize and reduce risk continuously.  

Learn more 

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser. This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows. The blog details the domain pattern, fingerprinting checks, infection chain, detection coverage, and hunting pivots that defenders can use to identify related activity.

Activity overview

Microsoft Threat Intelligence has been tracking a macOS ClickFix operation that distributes information-stealing malware through a large family of algorithmically named domains. Over several weeks of monitoring, Microsoft observed a notable shift in tradecraft: the same infrastructure moved from openly serving the malicious command in the served page’s HTML source to concealing the lure behind a server-side fingerprinting gate that reveals the payload only to visitors the server assesses as a genuine macOS target. The chain ultimately delivers information stealers such as MacSync or Atomic Stealer (AMOS).

This activity is consistent with the broader shift in macOS ClickFix tradecraft that Microsoft Threat Intelligence previously documented, in which threat actors instruct users to run Terminal commands that retrieve remotely hosted content rather than the traditional approach of delivering a disk image for manual installation. The cluster described here is notable for two reasons: its domains are mass-produced by a recognizable name generator, and it adopted server-side cloaking on existing infrastructure, giving defenders a clear before-and-after view of the same operation.

In this blog, we describe the campaign’s domain-generation pattern, the two delivery phases we observed, the fingerprinting gate that now fronts the infrastructure, and the end-to-end infection chain. We also provide hunting guidance, mitigation recommendations, and defanged indicators of compromise.

How ClickFix works 

ClickFix is a social-engineering technique where attackers persuade users to copy and run a command in Terminal instead of downloading a traditional macOS application. The lure usually appears as a fake verification step, software update, download error, or CAPTCHA, with the command disguised as something required to complete the action. Because execution starts from a user-run Terminal command rather than a downloaded app bundle, the flow can avoid parts of the normal macOS application trust path, including quarantine handling, code-signing evaluation, and notarization checks typically applied to downloaded applications.

In this campaign, ClickFix remains the delivery mechanism, but the important change is that the lure is no longer shown to every visitor. The page first profiles the visitor through a browser-fingerprinting gate and primarily requests consistent with a genuine macOS browser environment receive the fake “Download for macOS” page and copied Terminal command.

Figure 1a – The counterfeit “Download for macOS” page served to a qualifying visitor by a cloaked gate (apricotfilepoint[.]com). The page displays a forged “Verified Publisher” badge and offers a one-click Copy of an obfuscated curl one-liner.

Delivery is conditional. During analysis, the same URLs returned different content to different requests. In some case the macOS ClickFix lure, and in others an apparently benign decoy page.

In our testing, a request presenting a Windows browser received a decoy page such as a fake browser-extension or VPN landing page (Figure 1b) or a page impersonating an unrelated business such as a logistics and freight-forwarding company rather than the ClickFix lure. Because this decision is made server-side on a per-request basis, a given scan or visit may receive benign or decoy content and still be interacting with malicious infrastructure, so an apparently benign or look-alike response does not mean the domain is safe. We examine how the gate evaluates each request later in this post.

Figure 1b – A decoy page (a fake “Urban VPN Proxy” browser extension landing page) returned to non qualifying requests on the same domain (apricotfilepoint[.]com).

Campaign overview

The key change in this campaign is not the ClickFix lure itself, but the new layer placed in front of it. Microsoft Threat Intelligence confirmed more than 250 ClickFix front-end domains during the tracking window, and many followed a repeated naming pattern using the token “file” with dictionary-style words, such as filecopperbasket, filevelvettractor, fileoceanhammer, and filemarblegarden.

Some related domains place “filetoken in the middle or at the end, such as applefilevault, bananafastfile, and orangesmartfile, while others omit it completely, such as cloudsendhub and syncdatavault. Defenders should treat the naming pattern as a hunting pivot, not a complete signature. The stronger signal is the combination of dictionary-style domains, shared infrastructure behaviour, and the fingerprinting gate that controls who sees the ClickFix lure. This naming pattern is useful for clustering and hunting, but it is not the main story. The more important behaviour is that these domains now serve a browser-fingerprinting gate before showing any malicious content.

ClickFix moved from open pages to fingerprinting gates

In its earlier phase, the campaign’s domains served the lure directly. Retrieving one returned a “complete your download in Terminal” page with the malicious command present in the HTML. A scanner that does not execute JavaScript could recover the entire attack from the page source, including: the macOS paste-to-Terminal instructions, clipboard-write logic, obfuscated shell command, and encoded staging URL. Because the command was embedded in the served page, the domains were readily identifiable from passive data and static content matching.

The same infrastructure that previously exposed its ClickFix lure directly to visitors has evolved to employ a server-side fingerprinting gate. Rather than immediately presenting the malicious content, affected domains now return a minimal page containing only a lightweight JavaScript profiling routine(~2.5 KB size). To both casual visitors and automated scanners, the site may appear blank, inactive, or apparently benign.  In reality, the page serves as an evaluation layer that determines whether a visitor should be shown the ClickFix lure.

Across Microsoft Threat Intelligence’s investigation of this domain cluster, the outcomes were consistent. Simple crawlers received an empty, parked-looking page. JS-capable crawlers and sandbox environments that failed fingerprinting checks were served apparently benign decoy page, and requests presenting a genuine macOS browser fingerprint were shown the ClickFix lure.

Figure 2 – Earlier open-lure delivery compared with the current fingerprinting-gated delivery flow.

The fingerprinting gate

The gate profiles each visitor using a combination of browser, hardware, and runtime attributes, which are submitted to the server for evaluation. The following sections break down the categories of signals collected.

Browser profiling and environment collection

The first stage builds a browser fingerprint by collecting browser and page details from six objects exposed to the page: navigator, screen, window, document, location, and console. From navigator, it captures values such as platform, for example, “MacIntel”, user agent, language, vendor, and plugins, which establish the visitor’s claimed device and browser identity.

Display values from screen and window, including screen size, color depth, window dimensions, and pixel ratio, provide consistency signals for whether that identity is consistent with a real, non‑virtualized Mac environment. Page context from document and location, including title, referrer, character set, URL, and host, helps tie the fingerprint to the delivery context. The console object is also enumerated as part of the runtime surface and later helps identify developer tools or automated log-capturing environments. These values are merged into a single fingerprint object tagged with mode: “php” and later submitted back to the server for evaluation.

Figure 3a – The gate collects browser, system, and environment characteristics from multiple browser objects to build a visitor fingerprint.

Hardware validation

The gate then performs additional validation to determine whether the visitor resembles a genuine macOS user. One notable check uses WebGL, a browser graphics API normally used to render 2D and 3D content, to retrieve graphics-processing details from the visitor’s device. In this campaign, those WebGL-derived GPU signals help distinguish real Apple hardware from virtualized, emulated, software-rendered, or sandboxed environments before the server decides whether to return the ClickFix lure.

Figure 3b – WebGL-derived GPU signals can help distinguish likely Apple hardware from virtualized, emulated, software-rendered, or sandboxed environments.

Environment and behavioral checks

Additional probes evaluate characteristics such as timezone configuration, touch-input support, and whether the page is running inside an embedded frame. These signals help identify uncommon execution contexts that may indicate automated analysis or monitoring infrastructure.

The script records three signals:

  • timezoneOffset reads the system’s local timezone offset. Unusual or inconsistent values can contribute to identifying hosted infrastructure, sandbox environments, or otherwise atypical execution context.
  • frame checks whether the page is running inside an iframe. While common in legitimate scenarios, embedded execution contexts can also be associated with crawlers, analysis tools, and other automated environments, making this a useful qualification signal.
  • touchEvent checks for touch-input support. On desktop macOS systems, touch support is generally uncommon; unexpected touch capabilities can contribute to identifying an emulated, spoofed, or otherwise atypical environment.

Together, these checks help the gate distinguish a normal macOS desktop browser session from framed, headless, mobile, sandboxed, or automated environments before the server decides what content to return.

Figure 3c – Additional checks evaluate environmental attributes that can help differentiate legitimate users from automated systems.

Anti-analysis techniques

The gate also incorporates checks designed to detect browser instrumentation, automation frameworks, and modified browser behavior. Rather than simply determining whether a visitor is a bot, these probes appear intended to identify environments commonly used by researchers, crawlers, and security-analysis platforms. The implementation details described here are intended to help defenders recognize and detect gate behavior in malicious traffic-distribution infrastructure.

Figure 3d – The gate performs checks intended to identify browser instrumentation and automated analysis environments.

Two checks stand out. The first is a toString() counter. The script creates a temporary function whose toString() method increases a counter, then writes that function to the console. In a normal browser, this counter usually remains unchanged. However, if the developer console is open, or if a headless or log-capturing tool serializes console output, the function may be converted to a string, causing the counter to increase.

The second is a prototype-tamper probe built around a normal browser capability check. The gate calls canPlayType(“video/mp4”), which normally checks whether the browser supports MP4 playback. Here, that check is repurposed as a tripwire. A genuine browser handles the codec check natively and silently, but some automated or stealth browsers fake codec support in JavaScript. If that JavaScript path calls the hooked Array.prototype.includes, the gate sets the proto:true signal and flags the environment as potentially instrumented or automated.

Fingerprint submission

Once profiling is complete, the collected attributes are packaged and silently submitted back to the same server for evaluation. This process occurs without any user interaction or visible page content.

Figure 3e – Collected fingerprint data is submitted to the server, which determines whether the visitor qualifies to receive the ClickFix lure.

The following is the sample fingerprint the client sends to the server (values are representative and defanged):

Server-side victim selection

With the fingerprinting logic in place, the malicious content is no longer present in the initial page shown to the visitor. Instead, the server withholds the ClickFix lure until it receives and evaluates the submitted fingerprint, then returns one of two responses:

  • A bot, crawler, sandbox, virtual machine, unexpected geography, or unexpected browser receives a blank page, a benign decoy, or no content.
  • A genuine Mac and browser in an expected context receive the ClickFix lure: the counterfeit “Verified Publisher / Download for macOS” page and its poisoned one-liner. The targeting is primarily environment-based: genuine macOS users in an expected browser and request context receive the ClickFix lure.

This is a Traffic Distribution System (TDS) gate. We call it a TDS because the payload is delivered by server-side, on demand, only to visitors the operator selects security crawlers, researchers, and sandboxes are served no malicious content. This gating can make automated detection and analysis more difficult because those tools may see only an apparently benign response even though the infrastructure can deliver the ClickFix lure to selected macOS visitors.

Figure 4 – Server-side fingerprint evaluation and possible responses for selected and non-selected visitors.

Inside the infection chain: from gated lure to AMOS

The individual techniques used by the gate are not inherently malicious or novel. Browser fingerprinting, hardware validation checks, and Traffic Distribution System (TDS)-style visitor filtering are common in anti-abuse systems and have previously appeared in exploit-kit and malvertising ecosystems. What distinguishes this activity is how these techniques are integrated into a ClickFix campaign. Rather than immediately presenting a malicious command, the actor performs server-side victim qualification before revealing the lure, reducing visibility to researchers and automated security systems while maintaining access to intended macOS targets.

Using a qualified macOS target, we analyzed the complete infection chain. The activity began on a file<word><word>[.]com domain hosting the fingerprinting gate, which returned the counterfeit Download for macOS page (Figure 1a). A non-qualifying request received little or no visible content. The page uses GitHub-themed branding to mimic a legitimate software download experience; the branding is spoofed and does not indicate any compromise of GitHub.

When the victim runs the Terminal command, the campaign retrieves and executes a remote script from a /curl/<id> URL. The chain then progresses through multiple script stages before ultimately downloading and launching Atomic Stealer (AMOS), an information stealer that harvests credentials, browser and cryptocurrency wallet data, authentication stores, and other sensitive files before exfiltrating them. We detailed AMOS delivery across multiple macOS ClickFix lures in earlier research.

Because delivery is restricted to qualified visitors, the fingerprinting gate is often a more reliable hunting target than the downstream malware. Systems that inspect page content without executing client-side JavaScript can observe the gate logic directly, while environments that fail qualification are redirected to apparently benign or no content. Because these characteristics also appear in legitimate anti-bot implementations, evaluate combinations rather than single indicators. Useful signals include self-submitting fingerprinting forms, hidden fingerprint data fields, artifacts such as the mode:”php” parameter, and domains following the observed file naming convention; correlating several of these improves confidence and reduces false positives.

Mitigation and protection guidance

Organizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:

  • Educate users. Reinforce that no legitimate download, CAPTCHA, or verification step requires pasting a command into Terminal.
  • Monitor Terminal usage. Alert on Terminal or shell sessions that spawn curl, base64, gunzip, or osascript, particularly when initiated shortly after web browsing.
  • Detect native-tool abuse. Flag unusual sequences of macOS utilities such as curl piped to zsh, base64 -d, and xattr -c immediately preceding chmod +x.
  • Inspect outbound downloads. Monitor curl activity that retrieves encoded or compressed payloads from newly registered or low-reputation domains, including /curl/<hex-id> request paths.
  • Protect credential stores. Detect unauthorized access to keychain items, browser credential databases, SSH keys, and cryptocurrency wallet data.
  • Monitor data staging. Alert on the creation of archives of sensitive artifacts followed by HTTP POST exfiltration.
  • Block on infrastructure, not just front-end domains. Where validated, prioritize blocking known shared back end and staging hosts (for example, malware-c2 and the /curl/<id> staging hosts) over individual disposable front-end domains.
  • Hunt the generation pattern. Where feasible, alert the file<word><word> domain pattern rather than maintaining a list of individual domains.

On macOS 26.4 and later, Apple introduced a mitigation that displays a warning when a user attempts to paste a potentially malicious command into Terminal, directly addressing the ClickFix delivery mechanism.

When a user attempts to paste a potentially malicious command into Terminal, they will now see the following prompt:

Possible malware, Paste blocked

Your Mac has not been harmed. Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy. These instructions are commonly offered via websites, chat agents, apps, files, or a phone call.

Microsoft Defender XDR detections

Tactic Observed activity Microsoft Defender coverage 
 Initial Access Malicious webpage Microsoft Defender for SmartScreen
SmartScreen Detection Blocks webpage (Figure 5)
 Execution   User copies, pastes, and runs encoded instructions. The instructions are decoded, executable files are created from remote attacker infrastructure, and the malware implant is executed.Microsoft Defender for Endpoint
– Behavior:MacOS/SuspAmosExecution
– Malicious file execution  
– Behavior:MacOS/SuspOsascriptExec
– Malicious osascript execution
– Behavior:MacOS/SuspDownloadFileExec
– Behavior:MacOS/SuspInfoExfil
– Behavior:MacOS/SuspiciousActiviyGen.AE
– Suspicious file download and execution
Credential access Keychain extraction Behavior:MacOS/SuspKeyChainCopy.AB
Collection & Exfiltration  Browser data, crypto wallets, keys etc.  – Behavior:MacOS/SuspInfostealExec
– Behavior:MacOS/SuspCredCopy
– Behavior:MacOS/SuspPassSteal

Microsoft Defender SmartScreen displays a warning message to Microsoft Edge users when they visit a ClickFix landing page:

Figure 5. Microsoft Defender SmartScreen flagging a ClickFix webpage.

Microsoft Security Copilot  

Security Copilot customers can use the standalone experience to create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat: 

  • Incident investigation
  • Microsoft User analysis  
  • Threat actor profile  
  • Threat Intelligence 360 report based on MDTI article  
  • Vulnerability impact assessment

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Advanced hunting

The following query is an illustrative starting point. Validate table/column names and adjust the time range and indicators for your environment before running.

Known-IOC network sweep (mirrors a standard IOC hunt; populate from the IOC table and refresh as domains rotate)

let lookback = 30d;
let SuspiciousDomains = 
dynamic(["lemonfilewave.com","limefilescope.com","mangocloudfile.com"]);
DeviceNetworkEvents   
| where Timestamp >ago(lookback) 
| where RemoteUrl has_any (SuspiciousDomains)

Indicators of compromise (IOC)

Indicator Type Description 
applefilevault[.]comDomainClickFix Webpage
apricotfilepoint[.]comDomainClickFix Webpage 
bananafastfile[.]comDomainClickFix Webpage
cloudfilebridge[.]comDomainClickFix Webpage
filecedarwallet[.]online.DomainClickFix Webpage
filecopperbasket[.]sbsDomainClickFix Webpage
filecrimsonsignal[.]onlineDomainClickFix Webpage
filemarblegarden[.]sbsDomainClickFix Webpage
fileoceanhammer[.]sbsDomainClickFix Webpage
filerubyfolder[.]sbsDomainClickFix Webpage
filevelvettractor[.]sbsDomainClickFix Webpage
lemonfilewave[.]comDomainClickFix Webpage
limefilescope[.]comDomainClickFix Webpage
mangocloudfile[.]comDomainClickFix Webpage
orangesmartfile[.]comDomainClickFix Webpage
syncdatavault[.]comDomainClickFix Webpage
cloudsendhub[.]comDomainClickFix Webpage

References

Learn more

For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To get notified about new publications and to join discussions on social media, follow us on LinkedInX (formerly Twitter), and Bluesky.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.

Review our documentation to learn more about our real-time protection capabilities and see how to enable them within your organization.   

The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes.

Once executed, the malware searches developer workstations and continuous integration and continuous delivery (CI/CD) environments for npm, GitHub, cloud, and infrastructure credentials. It uses recovered identities to authenticate to npm, GitHub, Amazon Web Services (AWS), Kubernetes, and HashiCorp Vault, enabling it to enumerate packages, repositories, workflow secrets, cloud parameters, and secret-store values. Collected data is encrypted and transmitted through an attacker-controlled HTTPS endpoint, with GitHub repositories serving as a fallback exfiltration channel.

The payload’s most significant capability is automated propagation. After obtaining an npm publishing token, it enumerates packages available to the compromised identity, downloads their latest tarballs, inserts the malware and setup loader, adds a preinstall hook, increments the patch version, and republishes the modified packages. The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path.

In this blog, we’re sharing our analysis of this supply chain attack, along with protection, detection, amd hunting guidance. Organizations that installed an affected package with lifecycle scripts enabled should treat the associated developer workstation or build runner as potentially compromised. Investigations should prioritize credentials accessible to the affected identity, unauthorized npm releases, unexpected repository or workflow modifications, suspicious cloud and secret-store access, and artifacts produced by affected build systems. Organizations should revoke and rotate exposed credentials from a known-clean environment and rebuild affected systems and downstream artifacts from trusted sources.

Attack chain overview

The campaign appeared as a rapid sequence of unauthorized patch releases across more than 400 npm packages maintained by otherwise unrelated publishers. Many malicious versions had no corresponding source-code commit, pull request, tag, or legitimate release, indicating that the attackers modified and published package tarballs directly rather than compromising each public source repository.

Affected releases typically added a preinstall lifecycle script that launched a malicious file, setup.mjs, contained within the package, which launched the large, obfuscated Bun JavaScript bundle included in the package. Because npm runs preinstall scripts before installation completes, the payload could execute on developer workstations and build runners before application tests or conventional security checks began.

After execution, the malware performs the following actions:

  1. Determines whether it is running on a developer workstation or in a CI/CD environment. On workstations, it detaches itself to continue after installation; on CI/CD systems, it remains in the active job to access workflow secrets, runner credentials, and OpenID Connect (OIDC) publishing permissions. Both paths could support further package or repository propagation when suitable credentials are found.
  2. Collects credentials from local files, environment variables, command-line tools, and GitHub Actions runner memory.
  3. Authenticates to npm, GitHub, AWS, Kubernetes, and HashiCorp Vault to enumerate additional accessible resources and secrets.
  4. Encrypts and exfiltrates collected data through an HTTPS channel, using GitHub repositories as a fallback.
  5. Uses recovered npm publishing access to modify and republish additional packages.
  6. Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

The payload’s  package-propagation routine downloads each publisher’s latest release, inserts itself, increments the patch version, and publishes the resulting archive. This mechanism can rapidly transform one compromised npm identity into many malicious package releases.

Figure 1. Attack chain.

0. Initial publisher access

Evidence points towards stolen maintainer credentials as the attack vector for initial compromise. Later propagation used stolen npm publishing tokens and, in targeted workflows, GitHub Actions OIDC publishing access.

1. Payload startup and background execution

 The malicious npm package uses a lifecycle hook to launch its bundle.

During preflight, the payload checks the environment, exits on Russian-language systems, avoids duplicate instances, and starts a detached copy in the background on developer systems.

Figure 2. Platform identification and execution.

In CI environments, the payload remains attached so it can access credentials available to the active build job.

2. Initial credential discovery

The payload first collects information that is immediately available from the local system, shell, and GitHub Actions runner.

Figure 3. Credential discovery.

The shell collector attempts to obtain the GitHub CLI token and captures the values of all process environment variables. The filesystem collector searches credential files, shell histories, cloud configuration, Secure Shell (SSH) keys, and other sensitive locations.

3. Cloud and secret store enumeration

The recovered code then creates dedicated collectors for cloud and infrastructure services.

Figure 4. Credential enumeration.

These modules do not merely scan files for token patterns; they use available credentials to call service APIs, verify access, and retrieve additional secrets permitted to those identities.

The following snippet shows the authentication attempt made using the found credentials:

Figure 5. Credential validation.

4. GitHub credential theft and enumeration

Discovered GitHub tokens are validated before being used for additional collection or repository access.

Figure 6. GitHub credential collector.

The payload checks token scopes, enumerates writable repositories, and identifies repositories where workflow execution could expose additional secrets.

6. GitHub Actions OIDC abuse

The payload also contains a targeted publishing path for GitHub Actions workflows configured as npm trusted publishers.

Figure 7. Re-publishing package using GitHub OIDC token.

Packages published through this route can carry valid provenance because the publication originates from a legitimate workflow identity.

7. Exfiltration and fallback

Collected results are serialized as JSON, gzip-compressed, and encrypted with a randomly generated AES-256-GCM using a randomly generated 32-byte key and 12-byte initialization vector (IV). The AES key is then encrypted with the attacker’s RSA public key using RSA-OAEP-SHA256.

The payload first attempts delivery through an attacker-controlled dynamic HTTPS endpoint. The active domain can change through on-chain contract (0xE1f2395ee43e45A1556EC6438a88c31B83493103, selector 0x53ed5143) or, as a fallback, from a cryptographically verified signed GitHub commit (Signed fallback marker: thebeautifulmarchoftime). If that channel is unavailable, it creates a public GitHub repository with the description Shai-Hulud: Here We Go Again.

Encrypted results are committed as files such as: results-<timestamp>-<counter>.json.

At the time of analysis, the live contract returns npm-cache[.]com. Earlier candidates include pypi-get[.]com and js-mirror[.]com.

Figure 8. Exfiltrating stolen information.

In one fallback path, a stolen GitHub token is added separately using double Base64 encoding. This token field is encoded, not encrypted.

8. Repository persistence and secondary spread

The payload can use stolen GitHub credentials to inject the malware and supporting setup files into eligible repository branches. The recovered code targets Claude and Visual Studio Code configuration paths, including .claude/settings.json, .claude/setup.mjs, .vscode/tasks.json, and .vscode/setup.mjs.

These changes create a secondary infection route: future Claude or Visual Studio Code activity can restart the payload even after the original npm installation has completed. In a conditional GitHub fallback path, the payload also attempts to install a token-monitor component that maintains credential access and contains a destructive handler if the monitored token is revoked.

Figure 9. Injecting the malicious code into development ecosystems.

9. Worm behavior: Package modification and publication

The npm tokens found in collected data are checked for package-write permission and two-factor authentication (2FA)-bypass capability.

Figure 10. Republishing the package using stolen NPM token.
Figure 11. Malicious update to existing package and republishing.

The propagation routine downloads a package’s latest tarball, copies the current malware bundle into it, adds a loader, and replaces its lifecycle scripts. This creates the worm-like propagation pattern: one stolen token can produce malicious patch releases across every package available to that publisher. This also explains why malicious releases frequently appeared as an otherwise ordinary patch-version increment without corresponding source commits or pull requests.

Mitigation and protection guidance

Microsoft recommends the following mitigations to reduce the impact of this threat.

  • Update npm CLI to npm CLI v 12 and use the npm CLI min-release-age feature.
  • Review dependency trees, lockfiles, artifact repositories, and CI caches for the five compromised versions, including transitive references.
  • Pin known-good package versions.
  • Purge npm and yarn caches on affected developer endpoints and build hosts, especially if the compromised tarballs were written into shared CI caches.
  • Rotate credentials and secrets from a clean host if a build system or workstation imported a compromised version, because second-stage execution can expose tokens and compromise build integrity.
  • Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.
  • Organizations that produce software artifacts should also review their own release hardening because this incident appears consistent with CI/CD pipeline abuse through GitHub Actions OIDC publishing. Defenders should review token scopes, workflow approvals, protected environments, release provenance, and anomaly detection around automated package publication. Supply chain response cannot stop at host triage; it must also include verification that the release process itself has not been subverted.
  • After remediation, validate recovery deliberately. Rebuild affected projects from a known-good dependency baseline, confirm that compromised hashes are absent from package caches and artifact stores, and review endpoint telemetry for any lingering NodeJS directory artifacts such as Math_Symbol.js, Math_init.js,  or names similar to math_<guid>.js, or suspicious node child processes. For development organizations that share base images or golden build runners, rebuild those images as well so future jobs do not silently inherit poisoned caches or post-compromise persistence.

Indicators of compromise (IOC)

IndicatorDescription
54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668  setup.mjs (npm tarball preinstall loader)
fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb  setup.mjs (.claude and .vscode repository loader)
9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bccMath_*.js
npm-cache[.]comC2 domain
pypi-get[.]comC2 domain
js-mirror[.]comC2 domain
hxxps[:]//npm-cache[.]com:443/routerC2 URL

Microsoft Defender XDR detections

Microsoft Defender XDR customers can refer to the list of applicable detections below. Microsoft Defender XDR coordinates detection, prevention, investigation, and response across endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog.

TacticObserved activityMicrosoft Defender coverage
Initial access / ExecutionMalicious files embedded in compromised npm packages execute the embedded payload automatically through a malicious preinstall lifecycle hook.Microsoft Defender Antivirus
– Trojan:NPM/ShaiLoader.BY
– Trojan:NPM/MalBun.A
– Trojan:NPM/ShaiWorm.DAY!MTB

Microsoft Defender for Endpoint
– Suspicious Node.js process behavior
– Suspicious Node.js script execution
Execution / Defense evasionThe preinstall loader launches a heavily obfuscated Bun-based JavaScript payload designed to hinder analysis and evade Node.js-focused monitoring.Microsoft Defender Antivirus
– Behavior:Linux/SuspBunActivity.A
– Behavior:Win32/SuspBunActivity.A

Microsoft Defender for Endpoint 
– Suspicious usage of Bun runtime
– Suspicious installation of Bun runtime
– Suspicious Node.js process behavior
– Suspicious script execution via Bun
– Suspicious Node.js script execution  

Microsoft Defender for Cloud
– Suspicious npm supply-chain compromise activity detected
Credential access / CollectionThe malware searches developer workstations and CI/CD environments for npm, GitHub, cloud, Kubernetes, and secrets.Microsoft Defender for Endpoint
– Credential access attempt
– Suspicious cloud credential access
– Enumeration of files with sensitive data
– Suspicious access of sensitive files  

Microsoft Defender for Cloud
– Sha1-Hulud Campaign Detected: Possible command injection to exfiltrate credentials

Advanced hunting queries

Microsoft Defender XDR customers can run the following advanced hunting queries to find related activity in their networks:

Execution of the preinstall script

DeviceProcessEvents
    | where Timestamp > ago(3d)
    | where FileName in~ ("node", "node.exe")
    | where ProcessCommandLine in~ ("node setup.mjs", "node  setup.mjs")

CloudProcessEvents
    | where Timestamp > ago(3d)
    | where FileName in~ ("node", "node.exe")
    | where ProcessCommandLine in~ ("node setup.mjs", "node  setup.mjs")

Execution of second-stage JavaScript using Bun runtime

DeviceProcessEvents
    | where Timestamp > ago(3d)
    | where InitiatingProcessFileName in~ ("node", "node.exe")
    | where InitiatingProcessCommandLine in~ ("node setup.mjs", "node  setup.mjs")
    | where FileName in~ ("bun", "bun.exe")
    | where FolderPath contains "bun-dl-" or ProcessCommandLine has "node_modules"

Malicious JavaScript from malicious packages

DeviceFileEvents
| where Timestamp > ago(3d)
| where SHA256 in~ ("9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc", "fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb", "54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668")

Credential access by malicious JavaScript

DeviceProcessEvents
   | where Timestamp > ago(3d)
   | where ProcessCommandLine has_any ('gh auth token', 'gcloud config config-helper', 'az account get-access-token', "azd auth token")
   | where InitiatingProcessFileName in~ ("bun", "bun.exe")
   | where InitiatingProcessFolderPath contains "bun-dl-" or InitiatingProcessCommandLine has "node_modules"

Microsoft Security Copilot

Security Copilot customers can use the standalone experience to create their own prompts or run prebuilt promptbooks to automate investigation and response tasks related to this threat. Useful promptbooks for this activity include Incident investigation, Microsoft User analysis, Threat actor profile, Threat Intelligence 360 report based on MDTI intelligence, and Vulnerability impact assessment. Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

For this campaign, Security Copilot can help analysts summarize affected devices, pivot from the package hashes to endpoint evidence, identify hosts that communicated with the IPFS path or C2 infrastructure, and build remediation actions such as cache purge, credential rotation, and containment sequencing for impacted developer systems and build runners.

Threat intelligence reports

Microsoft customers can use Microsoft Defender XDR Threat analytics and related Microsoft threat intelligence reporting to stay current on the malicious activity, indicators, detection coverage, and recommended response actions associated with this compromise. These reports provide investigation context, protection guidance, and updated intelligence that security teams can use to prevent, mitigate, or respond to related activity in customer environments.

As with other active supply-chain investigations, defenders should monitor for updated intelligence on package status, additional affected versions, infrastructure changes, and newly surfaced post-compromise tradecraft. Microsoft will continue to incorporate validated indicators and detections into Microsoft security products as the investigation evolves.

Learn more

For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To get notified about new publications and to join discussions on social media, follow us on LinkedInX (formerly Twitter), and Bluesky.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.

Review our documentation to learn more about our real-time protection capabilities and see how to enable them within your organization.   

The post ChainDrop supply chain compromise: Anatomy of a self-propagating worm appeared first on Microsoft Security Blog.

Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

The calculus of cybersecurity has changed. AI is reshaping how organizations build, deploy, operate, and defend digital systems. AI-powered development tools, agents, and autonomous workflows are accelerating innovation but they are also introducing new attack surfaces, new trust boundaries, and new security challenges.

Microsoft has long helped organizations secure their digital estates using Zero Trust principles. That leadership was recently recognized by KuppingerCole analysts, which named Microsoft as the Overall Leader in its Zero Trust Platform Leadership Compass, ranking Microsoft highest for both product and innovation leadership.

The diagram illustrates a network of companies categorized into different roles such as Overall Leaders, Innovation Leaders, and Product Leaders, with Microsoft, Analysts, and other tech firms like Cisco and Zeronet as prominent examples.

As organizations accelerate AI adoption, secure software development becomes more important than ever. That’s why we are expanding the Zero Trust for AI strategy with two major additions: a new AI-focused Zero Trust Assessment experience and a new DevSecOps pillar in the Zero Trust Workshop. Together, they help organizations get ready for AI by assessing exposure, risks, prioritizing remediation, and securing AI-enabled development from source code to deployment.

  • Zero Trust Assessment tool updates: New set of assessment checks for AI, Security Operations (SecOps), and Infrastructure.
  • Zero Trust Workshop updates: New dedicated pillar focused on Developer Security (DevSecOps) and additional guidance for AI Memory.
  • New guidance: New practical guidance for security practitioners and a new e-book titled Zero Trust for AI, rebuilding security controls for autonomous and agentic systems.

This builds directly on the Zero Trust for AI strategy announced at RSA Conference 2026 and moves the conversation from architecture to implementation. If that announcement was about establishing Zero Trust for AI, this one is about operationalizing it: giving security, engineering, and platform teams the specific controls they need to act.

To learn more about our work in applying Zero Trust for AI and agents watch this Microsoft Mechanics video:

New AI pillar in Zero Trust Assessment tool

The Zero Trust Assessment provides an automated view of security posture by evaluating tenant configuration and activity signals across the environment and translating those findings into prioritized recommendations. As organizations adopt AI agents, Copilots, developer tools, and autonomous workflows, the Assessment helps security and platform teams establish a baseline, measure progress, and identify gaps across both traditional and AI-powered environments. It now includes expanded coverage with new pillars for AI, Security Operations, and Infrastructure (in addition to existing Identity, Devices, Network, and Data pillars), with Zero Trust for AI-focused checks that help organizations evaluate the controls required for secure AI adoption.

Additionally, enhanced reporting delivers both practitioner-level guidance and executive-ready summaries that communicate risk, progress, and next steps. Results map directly into the Zero Trust Workshop’s First, Then, Next framework, transforming assessment findings into a prioritized roadmap for remediation and implementation. Together, the Assessment and Workshop help organizations move from understanding risk to executing a structured plan for continuous improvement across their Zero Trust and AI security journey.

Dashboard screenshot displaying a Zero Trust Assessment overview with tenant info, assessment scores, and authentication methods. Key elements include user and device counts, compliance status with a red circular chart showing 2.0K non-compliant devices, and bar charts illustrating privileged and all users' strongest authentication methods.

What’s New in the Zero Trust Workshop

AI is fundamentally changing software development. Developers increasingly rely on AI assistants to generate code, recommend packages, create infrastructure configurations, and automate testing. While these capabilities accelerate delivery, they also amplify the consequences of governance gaps, excessive permissions, insecure dependencies, and compromised supply chains.

That is why Microsoft is introducing a new DevSecOps pillar (with 15 control groups and 91 tasks that help teams apply Zero Trust from source code to cloud deployment) in the Zero Trust Workshop. The pillar translates the three Zero Trust principles—verify explicitly, use least privilege, and assume breach—into practical guidance and controls for developer platforms, continuous integration and continuous delivery (CI/CD) pipelines, source repositories, dependencies, artifacts, and infrastructure-as-code.

The image is a diagram from a Zero Trust Workshop, illustrating a structured approach to cybersecurity, featuring various components like Identity, Devices, Data, Network, Infrastructure, Security, Operations, and Controls, with numbered values indicating different aspects such as lanes and controls, and emphasizing the importance of customized, integrated solutions for enhancing security.

The Zero Trust Workshop also improves the AI pillar to include guidance based on the Microsoft AI Memory framework, helping teams treat memory as a governed security boundary with clear intent, provenance, lifecycle visibility, and user control.

How to run Zero Trust Workshop

The Zero Trust Workshop follows a simple three-step motion: plan the right pillars and stakeholders, run the Zero Trust Assessment to establish a baseline, and use the facilitated workshop to turn findings into a 12- to 24-month roadmap.

Tasks are organized into First, Then, Next phases so teams can start with foundational controls and build momentum. The new DevSecOps pillar also highlights cross-pillar work that strengthens Identity, Infrastructure, and Security Operations, plus four tasks focused directly on AI-assisted development: code governance, tool allowlisting, data protection, and AI and machine learning pipeline supply-chain security.

Get practical guidance in the new Zero Trust for AI e-book

To help organizations navigate this shift, Microsoft recently published Zero Trust for AI: Rebuilding security controls for autonomous and agentic systems, a practical guide that applies Zero Trust principles to AI agents, tools, memory, data, and runtime operations. The e-book provides security leaders, architects, and practitioners with a framework for evaluating AI risks and implementing controls that scale with AI adoption.

Zero Trust for AI e-book

Practical guidance for securing AI systems.

The image is a diagram from a Zero Trust Workshop, illustrating a structured approach to cybersecurity, featuring various components like Identity, Devices, Data, Network, Infrastructure, Security, Operations, and Controls, with numbered values indicating different aspects such as lanes and controls, and emphasizing the importance of customized, integrated solutions for enhancing security.

Knowing what to do is one thing. Knowing how to operationalize it at scale is another. Our patterns and practices provide repeatable, proven approaches to the most complex AI security challenges, much like software design patterns offer reusable solutions to common engineering problems.

The table below highlights our practical recommendations aligned with Zero Trust principles to help practitioners translate strategy into concrete implementation.

Pattern and Practice GuidanceWhat it covers
Least privilege for AI agentsGuidance on applying Zero Trust to AI agents.
Zero Trust for source code accessGuidance on building Zero Trust protections for source code security.
Manage memory safety in agentic systemsGuidance for treating AI memory as a governed security boundary.
Protect the software supply chainGuidance for applying Zero Trust across the software development lifecycle.
Security adoption guidance for developmentGuidance on building secure development programs and governance.

How can partners help?

Partners can use the Zero Trust Assessment tool and Workshop to turn broad security interest into a focused, outcome-driven customer engagement. The Assessment tool helps establish a baseline across one or more Zero Trust pillars, including AI and DevSecOps scenarios, so customers can see where they are today and where to prioritize first. The Workshop then translates those findings into an executive summary, prioritized recommendations, and a phased roadmap. For customers, this creates a clear path from risk visibility to practical action plans that partners—as trusted advisors—can help prioritize and execute.

Learn how Microsoft partners deliver the Zero Trust Workshop through Frontier Accelerate for Security: Envisioning and POC.

Customer success stories

Ford Motor Company: Microsoft Security solutions offered Ford a unified, AI-powered platform to detect, address, and prevent cyberthreats across its hybrid environment. Grounded in a Zero Trust architecture, every access request—whether from users, devices, or applications—is continuously verified. This principle guided Ford’s approach to securing its hybrid environment, reinforcing protection before expanding visibility. Read more about how Ford builds trust across global operations.

The Microsoft security stack is more than technology. It contributes to Ford’s business in moving faster against cyberthreats and building a more secure future.”

—Weston Maggetti, Platform Manager, Ford Motor Company

SEB Group: SEB based its Zero Trust journey on identity, deploying Microsoft Entra ID and Microsoft Defender for Identity. It removed online identity exposure with Windows Hello for passwordless access, and extended protection with Microsoft Defender for Endpoint. Read more about how SEB implements Zero Trust.

Our Microsoft Security solutions are vital to our Zero Trust journey. That enhanced visibility helps to keep our SaaS (software as a service) landscape as simple as possible so that it’s easier to defend.”

—Ulf Larsson, Security Chief Technology Officer (CTO), SEB Group

Get started

To get started, use the Assessment and Workshop together to turn Zero Trust for AI into a practical implementation plan:

  • Use the Zero Trust Assessment tool to establish a baseline and prioritize the Workshop roadmap across Identity, Devices, Data, Infrastructure, and Network.
  • Run the Zero Trust Workshop with the new DevSecOps pillar to secure developer platforms, pipelines, code, and artifacts.
  • Complement your Zero Trust journey by assessing your posture and acting where attackers strike most. SecureNow, in Microsoft Security Exposure Management, helps you improve security across patching, open-source software, source code, internet-facing assets, and hygiene.

Learn more about Microsoft Security solutions on our website and bookmark the Microsoft Security blog for expert insights on security matters. Follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest cybersecurity news and updates.

The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog.

2026 Australian Census: the key dates, rules and questions answered

Every five years, the Australian Bureau of Statistics (ABS) takes a snapshot of Australia through the Census. The last one was held in 2021, which means households across the country are being contacted again in 2026.

The information collected helps show how Australia's population and households are changing and is used to plan services and infrastructure, from schools and hospitals to transport and housing.

This guide answers the key questions about the 2026 Census, including when to complete it, who needs to be counted, what happens if you're late, fines, privacy and what to do if you're away from home.

The ABS also has a handy guide to doing the Census. It's a useful overview, but we've gone a little further below by answering some of the practical questions it doesn't cover.

If you're unsure how the Census rules apply to your situation, call the Census Contact Centre on 1800 181 227 for advice.

When is the 2026 Census in Australia?

Census night for the 2026 Census is Tuesday August 11 2026. Think of it as the snapshot date: questions about where you're staying and who's in your household should reflect Tuesday night.

You can complete the form earlier if you've received your instructions and already know where you'll be on August 11. If your plans are still up in the air, it's better to wait until you know where you'll be staying.

Can you complete the Census after Census night?

Census night isn't a hard submission deadline. If you haven't completed the form on Tuesday August 11, you can still submit it on Wednesday, Thursday, Friday or later.

The ABS continues collecting forms and following up with households after Census night, so if you're late, complete it as soon as you can.

Australian Bureau of Statistics (ABS) Census 2026 people filling out forms

(Image credit: Australian Bureau of Statistics (ABS))

Is the 2026 Census compulsory in Australia?

Yes. Completing and submitting the 2026 Census is compulsory under the Census and Statistics Act 1905. But being late doesn't automatically mean you'll be fined.

The ABS first follows up with people who haven't completed their form. If someone still doesn't respond, they may be sent a written direction formally requiring them to provide the information. Ignoring that direction can lead to prosecution and a fine.

How much is the fine for not completing the Census?

If you've received a written direction and still don't comply, you can face a fine of up to AU$364 for each day you don't comply.

You can find more detail on the ABS's penalty provisions page.

Who needs to complete the 2026 Census?

The Census is designed to count everyone who's in Australia on Census night. That includes babies and children, international students, visitors and visa holders.

That doesn't mean everyone fills out their own form. In most homes, one person completes the household form for everyone staying there that night.

What if you don't have a fixed address?

You should still be included in the Census. If you're experiencing homelessness, the ABS provides Census field staff and other support to help you take part. If you're staying with someone on Census night, you can be included on their household form.

If you're travelling around Australia without a fixed or return address, such as camping, or in a caravan or boat, you still need to be included in the Census.

You'll generally be counted where you're staying on Census night. A caravan, tent or boat can be counted as your dwelling for the night, including at a caravan park, camping ground or marina.

If you don't have a usual address, the 2026 Census form lets you record that. For the usual-address question, the ABS says to select Elsewhere in Australia, choose Enter address manually and enter None in the suburb/locality box.

How do you complete the 2026 Census?

For most households, the process starts with instructions to complete the Census online. These include a Census number and temporary password you can use to access the form.

The ABS says the average household takes about 30 minutes to complete it.

What if you haven't received or have lost your Census letter?

You can still complete the Census. If you haven't received your instructions or no longer have them, you can get a Census number online or request a paper form.

Can you use a paper Census form?

Yes. Paper forms are available to anyone who wants one. Some households will receive a paper form automatically, while others can request one if they'd rather not complete the Census online.

If you need help completing the Census, the Census website has support options, including language and accessibility support. You can also contact the Census Contact Centre on 1800 181 227.

What if there are more than six people in your household?

A paper Census form can include up to six people. If more than six people are staying at your address on Census night, you can complete the Census online or request an extra paper form.

Can you complete your Census answers privately?

Yes. If you don't want other people in your household to see your answers, you can request a separate Census form and complete your information privately. The ABS explains how this works in its 2026 Census collection notice.

Can you change your Census answers after submitting the form?

Once a Census form has been submitted, the ABS says it can't be reopened or edited.

We couldn't find specific online guidance for what happens if you complete the Census early and your plans later change, so we called the ABS media line to clarify. The advice was to contact the Census Contact Centre on 1800 181 227. They'll talk you through the options if your plans have changed or you've realised you made a significant mistake.

Separately, the ABS has processes for dealing with multiple responses. If more than one Census form is submitted for the same person, it keeps the one containing the most complete information about that person.

Australian Bureau of Statistics (ABS) Census 2026 paper forms

(Image credit: Australian Bureau of Statistics (ABS))

What if you're away from home on Census night?

If you're away from your usual home on Census night, you'll generally be counted where you actually spend the night. Your usual address can record you as temporarily away.

That can include staying with friends or family or spending the night in a hotel, hospital or aged care home. The ABS also has arrangements for people travelling overnight by plane, train or bus.

If you're temporarily overseas on Census night, you won't be counted in the Census for that night.

What if you're working on Census night?

If you're working overnight but will return to your usual home on Wednesday August 12 and won't be included on a Census form elsewhere, the ABS says you can be included on the form for your usual home.

How are FIFO workers counted in the Census?

Fly-in, fly-out (FIFO) workers who are staying at a worksite or camp on Census night should generally be counted there. For example, if you normally live in Perth but you're at a mining camp in the Pilbara, you'd be counted at the camp and listed as temporarily away from your usual address in Perth.

Why might a Census field officer visit your home?

Census field officers may visit homes to deliver letters or forms, help people complete the Census or follow up after Census night where a completed form hasn't been received.

So a knock at the door doesn't automatically mean there's a problem. In some areas, field visits are simply part of how the Census is carried out.

How can you check if a Census worker is genuine?

If someone claiming to work for the Census contacts you and you're unsure whether they're genuine, verify them through official ABS channels rather than relying on the contact details they give you. Use the official Census website or call the Census Contact Centre on 1800 181 227.

How can you tell if a Census text, email or website is genuine?

The same caution applies to texts, emails and websites. The ABS says genuine Census text messages use the sender ID CENSUS, while texts about other ABS surveys use ABSGov. The official Census website uses a .gov.au address.

If a message doesn't look right, don't use the link it contains. Go directly to the official Census website. The ABS also has online safety guidance.

Australian Bureau of Statistics (ABS) Census 2026 person in doorway.

(Image credit: Australian Bureau of Statistics (ABS))

What questions are on the 2026 Census?

The 2026 Census contains 66 questions covering areas such as your household, age, cultural background, education, work and income, housing, religion and people who are away on Census night.

You can see the full breakdown in the ABS's 2026 Census topics and data release plan.

What's changed in the 2026 Census?

One of the biggest changes in 2026 is the addition of questions about gender and sexual orientation. Everyone is asked about their sex as recorded at birth, while people aged 16 and over are also asked about their gender and how they describe their sexual orientation.

The ABS says the change is intended to build a clearer picture of Australia's LGBTQ+ population and help inform health and community services. If you'd prefer not to answer, both the gender and sexual orientation questions include a prefer not to answer option.

People can also report up to four ancestries in the 2026 Census.

Do you have to answer every Census question?

No. The question about religion is explicitly marked as optional on the 2026 Census form.

The gender and sexual orientation questions for people aged 16 and over also include a "prefer not to answer" option. So, while taking part in the Census itself is compulsory, that doesn't mean every question requires you to provide a particular answer.

Is your 2026 Census information private?

Yes. Census information is protected by law, and the ABS says it doesn't share identifiable information from your Census form with other government departments or direct marketing companies.

That means your individual Census answers aren't handed to the Australian Taxation Office (ATO) to check your tax return or to Centrelink to check your eligibility for a payment.

You can read more in the ABS's 2026 Census Privacy Statement.

Is the Census anonymous?

No. The Census isn't anonymous because it asks for names and addresses. However, the ABS separates names and addresses from other Census information after processing.

When will the 2026 Census results be released?

The first 2026 Census results are due to be released in June 2027, with further data releases continuing into 2028.

Census data will be free to access through ABS tools including QuickStats, TableBuilder and ABS Data Maps.

Australian Bureau of Statistics (ABS) Census 2026 help

(Image credit: Australian Bureau of Statistics (ABS))

Improved connectivity is helping more Brits realise their dream — in both business and personal life

  • Vodafone uncovers a “nation full of drive” with 85% of Brits building towards a major ambition
  • Over half of those surveyed believe it is easier to find opportunities in the digital era
  • Vodafone launched the UK’s first Opportunity Hub in London, intended to provide advice and connections to ambitious visitors

Vodafone has released the results of research into how being connected has opened the door to people being able to pursue their goals.

With 40% of Brits feeling “more ambitious than ever” and a majority aiming to achieve major targets in personal and professional development, the research is part of VodafoneThree’s investment into building the UK’s best network.

Interestingly, the findings also highlight that key career events take place in our 20s and 30s, and accompany the successful Opportunity Hub event targeted at this age group.

Connecting unlocks opportunity

Vodafone’s survey found over half (55%) of Brits feel it is easier to find opportunities in the digital era, with 20% wishing they had started working toward their ambitions sooner. 42% believe greater connectivity has had a positive effect on reaching their goals, with 49% now “better placed” to achieve than they were 5 or 10 years ago.

The survey also uncovered the blocks to personal and professional ambitions. Unsurprisingly, financial constraints are the main barrier, with 22% admitting this. But lack of confidence at 13%, fear of failure (12%) and limited access to the tools needed for self-improvement (9%) are also mentioned as challenges.

However, life’s disruptions can be seen as launch points, with bereavement (27%) and redundancy (25%) catalysts for chasing ambitions, alongside parenthood (25%).

“Britain isn't short of ambition," a VodafoneThree spokesperson said, "the challenge is turning ambition into action. Our research shows that connectivity is increasingly part of that equation, with nearly two-thirds of would-be founders saying unreliable connectivity has held them back from starting a business locally.”

The KitchenAid KF2 might be the company's entry-level automatic coffee machine, but I think its unique feature makes it the most desirable

KitchenAid KF2 two-minute review

The KitchenAid KF2 Fully Automatic Espresso Machine is the entry-level model in the company’s six-strong range of automatic coffee machines, and was launched in mid-2026 alongside the KF3 and KF4.

It adopts the exact same slim build as its two siblings, making any of them ideal for smaller kitchens. It also benefits from the exact same Intelligrind coffee bean grinder, which automatically determines the best grind size depending on the beans you’ve put in. The brewing unit is the same also, and in my taste tests, I couldn’t notice any obvious difference between the three. That means you’re going to get a wonderful, tasty espresso with each use.

What sets the KF2 apart — and where KitchenAid has made cuts to bring the cost down — is its feature set regarding drink presets and general usability. It’s also the only model in KitchenAid’s entire fully automatic coffee machine range to rock a steam wand for foaming milk — the others all use a hose-based system. While this may seem like a drop down in specification, I personally found the steam wand to perform the best when making foamy lattes and cappuccinos. What’s more, a steam wand is inherently going to perform better with non-dairy milk as it allows for greater control over temperature.

As with the KF3 and KF4, the KitchenAid KF2 is capable of making iced-coffee drinks, although as I found in my KitchenAid KF3 review, the results are a little underwhelming. This is because the brewed espresso is hot enough to quickly melt the ice in your cup or glass, despite KitchenAid claiming it’s brewed at a lower temperature.

Where the KitchenAid KF2 loses points slightly is the fact it doesn’t offer user profiles. I’ve been used to having profiles for some time at home, as I currently use the KitchenAid KF4 and have previously used the Philips LatteGo 4400, which offer four profiles and two profiles, respectively. Having them makes brewing a coffee incredibly quick and simple: just select a profile, select a drink and that’s it.

The fact the KF2 doesn’t have profiles means that brewing a variety of coffees will take longer, as you’ll have to select the drink and adjust any settings each time. It therefore might not be the best option for larger households, but for households of one or two people it’s still worthy of consideration.

The other slight niggle I have, which affects the KF3 and KF4 also, is that the unit can go through water relatively quickly due to it running a rinse cycle on start up and shutdown. The shutdown cycle I can understand, but I find the start-up cycle to be a little redundant.

All things considered, the KitchenAid KF2 Fully Automatic Espresso Machine is another fantastic option from the brand. It brews a well-extracted espresso each and every time and the steam wand works wonders for milk-based drinks.

KitchenAid KF2 review: Price & availability

  • Launched in UK and US April 2026, Australia in July 2026
  • List price $799.99 / £699 / AU$1,099

The KitchenAid KF2 Fully Automatic Espresso Machine launched in the US and UK in April 2026, before making its way to Australia in July 2026. It has a list price of $799.99 / £699 / AU$1,099, making it the company’s most affordable fully automatic machine.

The step-up KF3 adds a small color display to improve navigation and usability, four customizable profiles and a larger menu of drink presets, with a list price $999.99 / £749 / AU$1,349.

The top-tier model, the KF4 ($1,299.99 / £899 / AU$1,599) offers much of the same functionality as the KF2 with regard to grinder and brewing unit. It gains even more recipes, a large color touchscreen and KitchenAid’s hose-based milk-foaming system, complete with milk carafe.

I’m of the opinion that the KF2’s steam wand is the best option for expertly-frothed milk and for using with non-dairy milk varieties, instantly giving the machine a leg up over its siblings. And, since the actual coffee-brewing process is the same across all three machines, the KF2 represents excellent value.

That being said, the Ninja Luxe Cafe Premier offers more in the way of features, including a dedicated cold brew setting and cold-extraction for improved iced-coffee results, along with intelligent grind and dosage settings. Its list price is less than the KF2’s at $599.99 / £549.99 / AU$799.99, although it too doesn’t offer user profiles either and requires more hands-on input.

  • Value score: 4 / 5

KitchenAid KF2 review: Specifications

Name

KitchenAid KF2 Fully Automatic Espresso Machine

Type

Bean-to-cup

Dimensions (H x W x D)

14.2 x 7.7 x 18.5 inches / 361 x 196 x 470mm

Weight

19.8lbs / 9kg

Water reservoir capacity

1.9 quarts / 1.8 liters

Milk frother

Yes, Pannarello steam wand

Bars of pressure

15

Noise level

72dB grinding, 60dB brewing

User profiles

0

KitchenAid KF2 review: Design

  • Compact size will suit smaller space
  • Steam wand suits plant-based milks
  • No dishwasher-safe components

KitchenAid KF2

(Image credit: Future)

Of the three new compact automatic models, the KitchenAid KF2 sticks out the most for a couple of reasons. Firstly, it’s only available in a matte black finish (the KF3 and KF4 also come in Porcelain White, which I’m personally a fan of), and secondly there’s no color display.

The matte black finish is still sleek and smart-looking, it must be said, although there is a shiny, fingerprint-loving panel on the front at the top. You’ll want to keep a cloth nearby to keep it looking its best.

I don’t consider the lack of a color display to be a huge negative against the KF2, as the backlit panel is bright and clear when selecting a drink and adjusting settings. The color screens on the rest of KitchenAid’s espresso machine range do offer useful assistance with features like images of the drink you want to make, but it’s not something I missed when testing the KF2.

Physically the KitchenAid KF2 is the same as the other two compact models released in 2026, measuring 14.2 x 7.7 x 18.5 inches / 361 x 196 x 470mm (H x W x D). This compact form makes it easy to place the unit on a kitchen counter, and should be especially ideal for those with smaller kitchens. A couple of built-in wheels on the bottom at rear of the machine aid with manoeuvring into position.

Interacting with the KF2 is done via five buttons on the front panel. These select the drink type, dosage and strength — each of which can be pressed multiple times to cycle through options — one to activate cleaning cycles and a final button to initiate and cancel brewing. Each button press reveals a different backlit symbol on the front panel which are relatively self-explanatory.

Drink type cycles between espresso, coffee and over ice, dose lets you choose between one or two servings (either two cups under the dispenser or one for a double serving), and strength is a scale of one to three. This refers to how much coffee is ground into the brewing unit, from 7g (setting one) to 14g (setting three).

The bean hopper recessed into the top of the KF2 is large enough to hold 250g worth of coffee beans, which is accessed via a removable lid. While this does mean there’s no visual indication as to how many beans are left, it does at least mean the beans are kept airtight and away from light, helping to retain their freshness. There’s also a small chute for pre-ground coffee, and a scoop is included in the box.

The 1.8L water tank slides in and out the rear of the machine and has an integrated handle to make the process simple, although I personally prefer a side-mounted tank like the one found on the Philips LatteGo 4400 as I find it makes refilling that little bit easier. However, the KF2’s tank does at least feature a hinged lid, allowing you to fill it up from a jug if you wish.

KitchenAid KF2 water tank
Future
KitchenAid KF2 water tank
Future

KitchenAid supplies a water filter with the KF2 that it claims lasts up to two months when used with standard tap water. If you use filtered water, its life can extend to up to six months. The filter can seem to be a little fiddly to install due to the water tank being so tall. Thankfully the included coffee scoop doubles up as a tool that clips onto the filter, giving you the extra length needed to screw it into place.

The drip tray is deep and extends virtually the full depth of the KF2, and has a large spout integrated into its rear for easy emptying. However, as I found with the KF3 and KF4, when you pour water out it can occasionally spill onto the front panel section as it can’t be removed. It’s not a huge dealbreaker, just prepare for a little extra clean up. Used coffee grounds are deposited into a removable bin in the center that can be tipped out when full. An icon will light up on the front panel to let you know when it’s time.

One of the standout features of the KitchenAid KF2, in my opinion, is its Pannarello steam wand used for milk foaming. I was surprised to find one used, not only because KitchenAid uses a proprietary hose-based system in the KF3 and KF4, but also because other brands such as De’Longhi and Philips have also turned their backs on steam wands (in general) in the pursuit of an entirely automatic coffee-making process.

Personally, I appreciate KitchenAid's choice to include a steam wand here, as it enables you to create genuine milk foam, even when using non-dairy alternatives. In my experience, the hose system on the KitchenAid KF3 and KF4, the LatteGo system on the Philips 4400, and the LatteCrema system on the De'Longhi Magnifica Evo Next all fell short of producing a satisfactory level of milk foam for my taste.

The use of the steam wand does mean there’s some hands-on input required, as you need to hold the jug (which isn’t included in the box) under the steam outlet until the foam reaches your desired level. There’s also no built-in thermometer, so unless you use a third-party thermometer, you’ll have to judge when the milk is ready based on touch.

Whether you are crafting a flat white or a cappuccino, the wand features a small slider for 'more foam' or 'less foam' to ensure you get the perfect texture. By opening and closing the integrated air intake, this slider regulates the airflow: increasing the intake pumps more air into the milk, which creates a more voluminous and aerated foam. Keeping it closed is ideal for texturizing milk for lattes that don’t require as high a level of foam.

The KF2 features thorough cleaning cycles, including the ability to completely evaporate the internal system of water. There are also programs for descaling and cleaning the brewing unit, which require you to press a variation of buttons to initiate. A complete set of useful instructions is included in the box. Do note that none of the removable parts are dishwasher safe.

  • Design score: 4.5 / 5

KitchenAid KF2 review: Performance

  • Consistently well-extracted espresso
  • Steam wand delivers silky, well-foamed milk
  • Lower brewing temperature for iced drinks still too hot

Coffee being poured from KitchenAid KF2

(Image credit: Future)

Having already reviewed the KF3, and knowing it uses the exact same brewing unit, I was expecting the same excellent results from the KitchenAid KF2. Fortunately my expectations were realised, as the compact KF2 produced a great-tasting espresso with each use.

Much of its success can be attributed to the IntelliGrind system that automatically determines the ideal grind size depending on your chosen beans. You can’t see the grinder at work, nor does the unit tell you what grind setting it’s chosen, you just have to put your trust in it to deliver optimal results. Your trust is rewarded.

However, if you're not completely satisfied with the crema or taste of your espresso, then the KF2 does offer the ability to manually adjust the grind to a finer or coarser level by way of a lever behind a compartment on the right-hand side of the machine. A finer setting is recommended for light-roast beans, while dark-roast beans benefit from a coarser setting. Since I was using medium-roast beans, I left the slider at the default setting in the middle.

Before you consider adjusting the grind level, you’ll first want to experiment with the strength of either the espresso or coffee drink presets. As mentioned earlier, there are only three coffee-based drink recipe presets: espresso, coffee and over ice. If you move up to the KF3 or KF4 you’ll gain recipes including latte macchiato, flat white and caffe latte, to name a few.

You can also adjust the volume of water used for each drink type, and the temperature it’s brewed at, by pressing and holding a specific set of buttons. You’ll find the full details in the supplied user manual. I was perfectly satisfied with the default settings, but it’s good to know KitchenAid offers the ability to personalize each drink.

Do note that if you do adjust any default settings, they will become the new norm until you change them again. Since there are no user profiles, you may want to consult with other people in your household before you make any tweaks.

Milk being steamed in pitcher using steam wand on KitchenAid KF2
Future
Milk being steamed using the wand on the KitchenAid KF2
Future
KitchenAid KF2
Future

If you want milk with your coffee, then the Pannarello steam wand is capable of producing thick, velvety foam that’s perfect for lattes, macchiatos and cappuccinos. It’s semi-automatic in use, as all you need to do is hold a milk pitcher under the wand and press the start button on the main unit (once you’ve cycled the ‘drink type’ menu through to ‘steam’). A word of warning, make sure you already have the steam wand submerged in milk. I pressed start with the pitcher still on the drip tray and ended up with milk all over the counter and myself.

A small slider on the side of the steam wand housing can be used to adjust the level of foam you achieve, either ‘less’ or ‘more’. In my tests this worked a charm, with the ‘more’ setting aerating the milk to such a high level that it nearly overflowed from the pitcher.

I much prefer the use of a steam wand compared to the hose systems used on the KF3 and KF4, as it’s capable of producing a much better level of froth. It’s also a hell of a lot easier to keep clean, as it doesn’t require constant rinse cycles to ensure the hose is free of residue. I actually wish the steam wand was featured on the company’s other machines.

Do note however that there’s no built-in thermometer to automatically detect when milk reaches your desired temperature. You’ll either have to invest in a dedicated one, or go off touch to determine when to shut the steam off. Also note that a milk pitcher isn’t included in the box. You can buy one directly from KitchenAid for $19.99 / AU$29. I wasn’t able to find a listing on the company’s UK store, but in all honesty, the pitcher available is relatively basic, so you could always get one from Amazon for the same or less money.

Where the KitchenAid KF2 falls down slightly — in a similar fashion to the KF3 and KF4 — is with its iced drinks function. KitchenAid has designed the KF2 to brew an espresso shot at a lower temperature compared to a regular shot when you select the ‘over ice’ drink type.

For starters, iced coffee fanatics will likely prefer a genuinely cold shot of coffee as opposed to having to pour a cooler shot of espresso over ice. Admittedly KItchenAid isn’t the only company to employ this function, as the Philips LatteGo machines also ask you to put some ice into a cup or glass before brewing an espresso.

However, I can’t agree with KitchenAid’s claim that the iced coffee espresso shot brews at a lower temperature, as I used a thermometer to check the temperature of a regular shot and iced shot, and both returned a measurements between 45ºC/113ºF and 50ºC/122ºF, which was hot enough to quickly melt the ice I had in my glass. It’s not necessarily a huge dealbreaker, but the fact remains there are other machines such as the De’Longhi Dedica Duo and the Jura J10 that are able to pour proper cold-extracted espresso for longer-lasting iced drinks.

It is, however, pleasing to find the KF2, like other KitchenAid espresso machines, is QuietMark-certified, signifying it should be whisper-quiet when grinding and brewing. And in reality, that’s certainly the case. I was able to record an average of 70dB while the machine was grinding and an average of 60dB when brewing. That, perhaps expectantly, puts it on par with the KF3 and KF4. That being said, we found the flagship KF8 to be quieter still with an average of 44dB during the entire coffee-making process.

Control panel of KitchenAid KF2

(Image credit: Future)
  • Performance score: 4.5 / 5

Should you buy the KitchenAid KF2?

KitchenAid KF2 score card

Attribute

Notes

Score

Value

KitchenAid's most affordable fully auto machine offers the best combination of features in my opinion.

4.5/5

Design

Compact form will suit smaller kitchens, although lack of user profiles can add time to brewing process.

4/5

Performance

Excellent coffee and milk frothing, but iced options are a little disappointing.

4.5/5

Buy it if...

You’re short on space

The KF2 is one of the more compact coffee machines we’ve tested, and will slot nearly into smaller kitchen spaces.

You want the essentials done well

The KF2 might not offer an extensive menu of preset drink recipes, but it nails the basics of espresso and coffee.

You drink lattes and cappuccinos

The Pannarello steam wand works wonders to produce thick, velvety foam that’s perfect for milk-based coffee drinks — and it’s great for non-dairy varieties too.

Don't buy it if...

You want a more hands-off approach

With no user profiles and manual input needed for milk, the KF2 isn’t as ‘set and forget’ as many other fully automatic coffee machines.

You don’t like the color black

The KitchenAid KF2 is only available in a matte black finish, which could clash with your kitchen decor.

You like to drink cold brew

The KitchenAid KF2 can’t make it, and its iced coffee espresso shot is still hot enough to quickly melt ice cubes.

KitchenAid KF2 review: Also consider

KitchenAid KF3

This step-up model offers a wider range of drink presets and can automatically foam milk for you via a hose-based system. It also offers four user profiles to save personalized drinks.

Read my full KitchenAid KF3 review

Lavazza A Modo Mio Jolie Evo

If you have a small kitchen and just want a fuss-free coffee, this Lavazza pod coffee machine could be just the thing for you. Espresso is superb and it’s incredibly simple to use.

Read our full Lavazza A Modo Mio Jolie Evo review

Ninja Luxe Café

This 3-in-1 bean-to-cup espresso machine can handle virtually any coffee-based drink you could wish for, including filter and cold brew. It takes care of most of the leg work for you, and is regularly discounted.

Read our full Ninja Luxe Cafe review

How I tested the KitchenAid KF2

KitchenAid KF2

(Image credit: Future)

I used the KitchenAid KF2 over a one-week period. I was confident knowing how to use the machine, having previously reviewed the KF3 and from using the KF4 on a daily basis at home.

I prepared all of the available drink recipes — espresso, coffee and over ice — and used a thermometer to test the temperature of the ‘over ice’ espresso shot to determine if it was actually brewed at a lower temperature, as KitchenAid claims.

I also used the integrated steam wand in both its ‘less foam’ and ‘more foam’ settings to determine if there was indeed a difference in results. I also tested it with dairy milk and a barista-style oat milk to find out if it worked well with non-dairy milk varieties.

Read more about how we test

First reviewed August 2026

What is the release date for Stuart Fails to Save the Universe episode 4 on HBO Max?

The Big Bang Theory's Bernadette as a demon is something I didn't think I'd ever see in Stuart Fails to Save the Universe — but, now that I have, it somehow makes complete sense.

Last week's episode saw us meet her in a wizarding world but, in this week's entry we're swapping the magical action for something a little more One Flew Over the Cuckoo's Nest-coded.

But who, if anyone, really is crazy? And when does Stuart Fails to Save the Universe episode 4 arrive on HBO Max?

What time can I watch Stuart Fails to Save the Universe episode 4 on HBO Max?

For US viewers, Stuart Fails to Save the Universe episode 4 will drop on Thursday, August 13 at 6pm PT/ 9pm ET.

Internationally, you're looking out for these timings:

  • US – Thursday, August 13 at 6pm PT / 9pm ET
  • Canada – Thursday, August 13 at 6pm PT / 9pm ET
  • UK – Friday, August 14 at 2am BST
  • India – Friday, August 14 at 6:30am IST
  • Singapore – Friday, August 14 at 9am SGT
  • Australia – Friday, August 14 at 11am AEDT
  • New Zealand – Friday, August 14 at 12pm NZDT

When do new episodes of Stuart Fails to Save the Universe come out?

Bert, Kripke, Denise and Stuart are interrogated while wearing military uniform

Me and who being suited and booted for more episodes? (Image credit: HBO Max)

New episodes of Stuart Fails to Save the Universe will make landfall every Thursday in the US and on Fridays everywhere else. Here are the all-important dates you need to know about:

  • Episode 1: out now
  • Episode 2: out now
  • Episode 3: out now
  • Episode 4: August 13
  • Episode 5: August 20
  • Episode 6: August 27
  • Episode 7: September 3
  • Episode 8: September 10
  • Episode 9: September 17
  • Episode 10: September 24

Amazon reportedly uses 45-year-old rules to get around AI data center opposition - California residents left fuming after Gilroy facility begins construction

  • Amazon revealed plans to build Gilroy, California data center were first submitted in 2020
  • Gilroy citizens have accused the city council of inadequate communications concerning the development
  • The 438,500-square-foot data center occupies a 56-acre chunk of farmland 30 miles south of San Jose

Citizens of Gilroy, California, have expressed dismay at the building of an Amazon data center, which they say they were not informed of - and when one resident attempted to lodge a complaint, she was told that comments on the plans were closed in 2024 – long before most citizens were even aware of the planned installation.

Occupying a 56-acre area of farmland between a Walmart and a local shopping center, the Amazon project appears to have been quietly pushed through using obfuscation and clever use of 45-year-old planning laws.

Amazon has apparently made provision to divert wastewater to the data center, and donated money for local spending. Meanwhile, the city mayor has responded to the concerns by likening the water-and power-hungry Amazon data center to a food distribution center that was also recently approved.

Opposition and sponsorships

Utilizing the old city zoning rule – originally intended for industrial development along a freeway – has enabled the data center to proceed into full development without planning scrutiny from residents. However, the apparent collaboration between Amazon and the Gilroy city council and mayor has not gone unnoticed, with opposition organized against the project.

One of those organizers, 21-year-old college student Landon Sepulveda, indicated to the Wall Street Journal that there was a trust issue between the population and the city administrators. “These processes were not enough for the citizens of Gilroy to do anything about it. We’ve elected them to tell us, and we shouldn’t have to watch over their shoulders.”

Another citizen, elementary school teacher Coleen Crew, told a recent council meeting “Many if not most residents first learned about this project after construction had already begun.”

Amazon and the Gilroy council have been at pains to highlight the advantages of the deal, citing jobs, tax revenue, and that solution to concerns over water use. Amazon has also donated $1 million for a new city fire truck, and donated money to non-profits and the city’s annal Gilroy Garlic Festival.

Mayor Bozzo and AWS

Responding to public dismay over the development, Mayor Greg Bozzo has highlighted an “opportunity to change the way that we do business in Gilroy. We’re adapting to the times.”

Meanwhile, Amazon Web Services’ VP of economic development Roger Wehner claims the project “followed standard approval processes.” He added: “We’ve since met directly with residents and hosted an open house to hear feedback and answer questions.”

The challenges and advantages of data centers seem to be the modern day equivalent of opposition to nuclear plants from 50 years ago. While the data center’s continued construction seems inevitable, and Amazon has made some generous provisions, it is disappointing that the city’s residents were not informed of the development – and that might be the biggest problem here.

Better coffee — and now better NBN? Melburnians may have added another bragging right over Sydneysiders

Adding more fuel to the fire over which city is actually Australia’s best place to live, those residing in the all-seasons-in-a-day city of Melbourne have a new statistic on their side — and it all relates to fixed-line broadband speed.

Ookla, the company behind the hugely popular Speedtest tool that helps anyone diagnose their home internet speeds, has published its latest Global Index rankings, revealing median fixed-broadband download speeds by country and city.

As a country, Australia is slowly but surely moving up the table. There was a time we ranked as low as 86th, but we now sit at 50th, with a median fixed-broadband download speed of 162.34Mbps.

That improvement follows NBN Co’s September 2025 speed-tier shake-up, which introduced a 2Gbps wholesale option for eligible FTTP and HFC premises, alongside faster speeds on several existing higher-end tiers. Of course, not every Australian can access 2Gbps just yet — and, as we’ll see, the plan you choose is only one part of the equation.

For context, Singapore takes the crown with a median download speed of 447.75Mbps. One can only dream of a day when that becomes a reality Down Under.

Why the huge gap?

There are several reasons why Australia trails the pack so dramatically — although with 141 other countries clocking slower speeds, things could certainly be worse — and, in my mind, one of the most obvious is that many Australians are still connected to comparatively slow NBN plans.

The Australian Competition & Consumer Commission publishes a quarterly Wholesale Market Indicators Report that provides an overview of active NBN connections and their download data rates.

The most recent report, covering the March quarter of 2026 and published in July, revealed there were just over 2.665 million active 50Mbps NBN connections, out of a total of 8.839 million residential broadband services. That works out to around 30.2%.

A 50Mbps plan naturally puts a ceiling on the speed a customer can record in a Speedtest. If enough users on lower-speed tiers are represented in Ookla’s sample, that will bring the national median down.

One relatively straightforward way for Australia’s international standing to improve, then, is for more eligible households to take advantage of NBN Co’s free fibre upgrade. The program is open to millions of eligible FTTN and FTTC premises, allowing them to upgrade to FTTP if they take out an eligible high-speed service — such as one of the best NBN 500 plans.

A fixed-line civil war

Move the slider over to ‘City’ and the results become much more varied, with cities from North and South America, Asia and Europe all jostling for position. Valparaíso in Chile takes the crown with a huge 425.84Mbps, followed by Abu Dhabi with 399.92Mbps, for example.

Australian cities evidently have some work to do. Scroll down to position 64 and you hit Melbourne with a median download speed of 177.69Mbps — faster than Australia’s national median, it must be said — while Sydney trails behind in position 76 with a meagre 149.91Mbps.

A difference of 27.78Mbps might not sound like much, but Melbourne’s median result is around 18.5% faster than Sydney’s. When intercity tensions are already high, that’s a huge bragging right for the southerners.

Wait, we can (try to) explain

Nobody ever wants to be seen as the weaker of two, and while the reported figures are great news for people in Victoria, there is potentially a plethora of factors at play that pave the way for a Melbourne victory.

We’re not here to make excuses, of course, but there are plenty of unknowns.

Firstly, there could simply be a larger proportion of Melburnians connected via superior fibre-to-the-premises infrastructure. FTTP allows households to access the fastest NBN plans, including the newer multi-gigabit options where available.

While it’s not totally conclusive, there is some evidence to support this idea. That evidence is publicly available technology-mix figures, although they’re reported at a state level, rather than for Greater Melbourne and Greater Sydney specifically. Data compiled from NBN rollout information indicates Victoria has a higher share of premises using FTTP than NSW — roughly 66% versus 60% — while it also indicates there are more active connections on the inferior fibre to the node (FTTN) connection type in NSW too.

This doesn’t completely settle the argument. The figures not only include regional areas, but they also show the technology available to a property, as opposed to an active plan supplying an address.

All fixed-line connections are welcome

Furthermore, on the subject of NBN, Ookla’s Speedtest results don’t only capture NBN connections, but fixed-broadband tests from other fixed networks too, including private fibre operators. Both Melbourne and Sydney are home to several such networks, including Vocus, GigaComm and OptiComm, while Melbourne also has DGtek — a private FTTP network concentrated in the city’s CBD and inner south-east.

Exact figures for active connections on those networks are tricky to come by. But if Melbourne has a higher concentration of people connected to these kinds of high-speed private fibre services, they could be recording considerably quicker test results and helping push its city median upwards.

Not telling the complete story?

Another excuse potential explainer is the way Ookla collects its data. Whereas the ACCC’s Measuring Broadband Report — which published its final instalment in June 2026 — monitors a selected group of Australian homes across nine popular ISPs, Ookla receives data when people choose to run a Speedtest.

This doesn’t mean someone repeatedly checking their connection can single-handedly skew the data, as Ookla averages each unique user’s results into a single sample for the relevant time period and location. Still, the results are dependent on who chooses to test. Melbourne’s sample could contain a different mix of internet plans, connection technologies, devices and Wi-Fi setups than Sydney’s.

TP-Link Deco BE63 Lifestyle 2

(Image credit: TP-Link)

When did you last check your Wi-Fi router?

Home equipment can make a considerable difference too. A household with a Wi-Fi 5 router tucked away in a cupboard, a busy 2.4GHz network and a phone testing from the other end of the house could record a much slower result than the same connection tested over Ethernet.

On the flip side, a newer Wi-Fi 6E or Wi-Fi 7 router, a properly positioned mesh system and a compatible device can give a household a far better chance of getting close to the speeds it actually pays for. That doesn’t make the underlying internet plan any faster, of course — it simply means the home network is less likely to be the bottleneck.

If your own Speedtest result seems suspiciously low, it may be worth checking out our guide to the best mesh Wi-Fi systems to find out if your home could benefit from an upgrade.

And, trying to claw a point back for Sydney, it can be argued that people often run a speed test when their internet connection starts lagging. While Melbourne’s median tested speed is higher, that doesn’t necessarily mean every connection in the city is consistently faster or more reliable.

Virginia cracks down on electricity firms hiking prices for AI data centers — move could save ‘hundreds of millions of dollars’ for everyday users

  • Virginia now makes data centers pay for their own power lines
  • Virginia hosts 570 data centers, more than any other US state
  • Spanberger says the policy could save residents hundreds of millions

The US state of Virginia is requiring data centers to cover electricity infrastructure costs created specifically by their rapidly growing power demands.

The move comes as electricity prices across the state have risen sharply alongside the expansion of artificial intelligence facilities.

State officials say the new requirement could prevent ordinary electricity customers from carrying costs associated with large data center developments.

Data centers face higher infrastructure costs

Virginia has become the largest data center hub in the United States, with at least 570 facilities operating across the state.

Their growing electricity consumption has required major investments in transmission infrastructure, increasing pressure on the regional power system.

The State Corporation Commission, Virginia’s public utility regulator, has ordered data centers to pay for transmission infrastructure used exclusively by their facilities.

The requirement means utilities can no longer spread those dedicated infrastructure costs across their wider customer base.

Electricity prices in the region have already increased substantially, with PJM Interconnection raising prices by 76% during recent capacity market changes.

Monitoring Analytics, an independent market watchdog, has attributed much of that increase to growing demand from data centers.

The issue has become politically important as artificial intelligence companies continue expanding computing capacity across Virginia.

Some local authorities have even asked employees and institutions, including schools, to reduce electricity consumption during periods of high demand.

"We are taking real steps to address rising energy costs for Virginians," said the Governor of Virginia, Abigail Spanberger.

"I will continue to work with the General Assembly and take action to make sure data centers pay their fair share, adhere to strict environmental standards, and listen to the concerns of local communities.”

Washington’s promise reaches the states

The Virginia decision follows President Donald Trump’s effort to make major AI companies finance infrastructure required by their expanding operations.

Trump met leading AI companies at the White House in March and urged them to “pay their own way” for necessary infrastructure.

The administration expanded that approach in July by calling on governors, utilities, and data center developers to follow similar principles.

Critics have questioned whether voluntary commitments can significantly change electricity costs without enforceable state or federal requirements.

Virginia is currently among the few states taking concrete action against rising electricity costs linked to large electricity users.

Oregon has also introduced higher electricity rates for data centers consuming at least 20 MW, under provisions contained within its POWER Act.

Portland General Electric subsequently increased rates for those large consumers by 30%, while residential electricity costs fell by approximately 1.3%.

The Virginia approach differs by focusing specifically on infrastructure dedicated to individual data center projects.

The policy could become increasingly important as AI companies expand AI tools requiring increasingly powerful computing facilities and greater electricity supplies.

If other states adopt similar requirements, data centers could face more direct responsibility for infrastructure costs they generate.

For Virginia households, however, the immediate question is whether the policy actually prevents future electricity increases rather than simply changing who pays existing infrastructure bills.

Spanberger said the state expects the measure to save Virginians “hundreds of millions of dollars” while requiring data centers to pay their fair share.

Via Tom's Hardware

Google logo on a black background next to text reading 'Click to follow TechRadar'

Quordle hints and answers for Tuesday, August 11 (game #1660)

Looking for a different day?

A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Monday's puzzle instead then click here: Quordle hints and answers for Monday, August 10 (game #1659).

Quordle was one of the original Wordle alternatives and is still going strong now more than 1,500 games later. It offers a genuine challenge, though, so read on if you need some Quordle hints today — or scroll down further for the answers.

Enjoy playing word games? You can also check out my NYT Connections today and NYT Strands today pages for hints and answers for those puzzles, while Marc's Wordle today column covers the original viral word game.

SPOILER WARNING: Information about Quordle today is below, so don't read on if you don't want to know the answers.

Quordle today (game #1660) — hint #1 — Vowels

How many different vowels are in Quordle today?

The number of different vowels in Quordle today is 4*.

* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too).

Quordle today (game #1660) — hint #2 — repeated letters

Do any of today's Quordle answers contain repeated letters?

The number of Quordle answers containing a repeated letter today is 0.

Quordle today (game #1660) — hint #3 — uncommon letters

Do the letters Q, Z, X or J appear in Quordle today?

• No. None of Q, Z, X or J appear among today's Quordle answers.

Quordle today (game #1660) — hint #4 — starting letters (1)

Do any of today's Quordle puzzles start with the same letter?

The number of today's Quordle answers starting with the same letter is 0.

If you just want to know the answers at this stage, simply scroll down. If you're not ready yet then here's one more clue to make things a lot easier:

Quordle today (game #1660) — hint #5 — starting letters (2)

What letters do today's Quordle answers start with?

• O

• B

• T

• S

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

Quordle today (game #1660) — the answers

Quordle answers for game 1660 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle, game #1660, are…

  • ONSET
  • BRAWL
  • TEPID
  • SLANG

Sometimes I like to look at the four Quordle words as a creative writing task and imagine a story, or the opening of a story based on them.

Most days, it’s impossible but today is a good one — an urban tale of young men who are quick with their fists but whose lack of streetwise vernacular is embarrassingly poor.

Daily Sequence today (game #1660) — the answers

Quordle Daily Sequence answers for game 1660 on a yellow background

(Image credit: Merriam-Webster)

The answers to today's Quordle Daily Sequence, game #1660, are…

  • DONUT
  • FLESH
  • PLANK
  • BIDDY

Quordle answers: The past 20

  • Quordle #1659, Monday, 10 August: GAVEL, CRUSH, SPEED, ETHOS
  • Quordle #1658, Sunday, 9 August: KAPPA, WIDEN, FOLIO, STEEP
  • Quordle #1657, Saturday, 8 August: FUROR, BUGLE, REUSE, SCOOP
  • Quordle #1656, Friday, 7 August: AMISS, SHIRK, SALSA, RABBI
  • Quordle #1655, Thursday, 6 August: AMUSE, BRAND, CEDAR, BLURB
  • Quordle #1654, Wednesday, 5 August: MOUND, WRONG, STOOD, WEIRD
  • Quordle #1653, Tuesday, 4 August: GOOEY, TARDY, HUMAN, CHALK
  • Quordle #1652, Monday, 3 August: FUNGI, MUDDY, DEBUT, MANIA
  • Quordle #1651, Sunday, 2 August: BOOTH, EASEL, REACH, MAKER
  • Quordle #1650, Saturday, 1 August: OMEGA, BIRCH, SMOCK, EERIE
  • Quordle #1649, Friday, 31 July: MANIA, SINGE, STOOL, LOFTY
  • Quordle #1648, Thursday, 30 July: MODAL, IDLER, CHUMP, LUMPY
  • Quordle #1647, Wednesday, 29 July: GAWKY, ALLOY, AUDIT, LATCH
  • Quordle #1646, Tuesday, 28 July: SMITE, ROACH, RUDDY, GLOBE
  • Quordle #1645, Monday, 27 July: TAFFY, FIGHT, GUILD, WAGER
  • Quordle #1644, Sunday, 26 July: STOMP, LIMIT, FUNKY, STEAD
  • Quordle #1643, Saturday, 25 July: SALON, SHEEN, BURST, GOURD
  • Quordle #1642, Friday, 24 July: DOLLY, EDIFY, LAGER, PRANK
  • Quordle #1641, Thursday, 23 July: LADEN, EVICT, WOVEN, SHIRE
  • Quordle #1640, Wednesday, 22 July: COYLY, SINGE, AWASH, AWOKE

NYT Strands hints and answers for Tuesday, August 11 (game #891)

Looking for a different day?

A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Monday's puzzle instead then click here: NYT Strands hints and answers for Monday, August 10 (game #890).

Strands is the NYT's latest word game after the likes of Wordle, Spelling Bee and Connections – and it's great fun. It can be difficult, though, so read on for my Strands hints.

Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc's Wordle today page for the original viral word game.

SPOILER WARNING: Information about NYT Strands today is below, so don't read on if you don't want to know the answers.

NYT Strands today (game #891) - hint #1 - today's theme

What is the theme of today's NYT Strands?

Today's NYT Strands theme is… Fresh from the market

NYT Strands today (game #891) - hint #2 - clue words

Play any of these words to unlock the in-game hints system.

  • CHEEP
  • HINTS
  • CHIVE
  • COME
  • TRACE
  • MANOR

NYT Strands today (game #891) - hint #3 - spangram letters

How many letters are in today's spangram?

Spangram has 13 letters

NYT Strands today (game #891) - hint #4 - spangram position

What are two sides of the board that today's spangram touches?

First side: left, 5th row

Last side: right, 8th row

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

NYT Strands today (game #891) - the answers

NYT Strands answers for game 891 on a blue background

(Image credit: New York Times)

The answers to today's Strands, game #891, are…

  • TOMATO
  • ZUCCHINI
  • PEPPER
  • MELON
  • CORN
  • CARROT
  • SPANGRAM: SUMMERHARVEST
  • My rating: Easy
  • My score: Perfect

One for the veggie lovers among us.

ZUCCHINI took me a while to put together, in part because I come from a land where we call zucchini courgettes, but mainly because I can’t spell and missed the double C.

This misstep aside I sped through today’s game, finding it harder to find a decent crop of non-game words.

Yesterday's NYT Strands answers (Monday, August 10, game #890)

  • DATA
  • FACTS
  • FIGURES
  • STATISTICS
  • SPECIFICS
  • SPANGRAM: PROOFPOSITIVE

What is NYT Strands?

Strands is the NYT's not-so-new-any-more word game, following Wordle and Connections. It's now a fully fledged member of the NYT's games stable that has been running for a year and which can be played on the NYT Games site on desktop or mobile.

I've got a full guide to how to play NYT Strands, complete with tips for solving it, so check that out if you're struggling to beat it each day.

NYT Connections hints and answers for Tuesday, August 11 (game #1157)

Looking for a different day?

A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Monday's puzzle instead then click here: NYT Connections hints and answers for Monday, August 10 (game #1156).

Good morning! Let's play Connections, the NYT's clever word game that challenges you to group answers in various categories. It can be tough, so read on if you need Connections hints.

What should you do once you've finished? Why, play some more word games of course. I've also got daily Strands hints and answers and Quordle hints and answers articles if you need help for those too, while Marc's Wordle today page covers the original viral word game.

SPOILER WARNING: Information about NYT Connections today is below, so don't read on if you don't want to know the answers.

NYT Connections today (game #1157) - today's words

NYT Connections hints for game 1157 on a purple background

(Image credit: New York Times)

Today's NYT Connections words are…

  • TOAST
  • AYE
  • BRAVO
  • SOLD
  • BET
  • DONE
  • HISTORY
  • KNOWS
  • HARE
  • GOING
  • THROUGH
  • TWICE
  • ONCE
  • SUNK
  • TUNG
  • USA

NYT Connections today (game #1157) - hint #1 - group hints

What are some clues for today's NYT Connections groups?

  • YELLOW: Well and truly over
  • GREEN: On your TV
  • BLUE: Said after the final bid
  • PURPLE: Sounds like it’s on your face

Need more clues?

We're firmly in spoiler territory now, but read on if you want to know what the four theme answers are for today's NYT Connections puzzles…

NYT Connections today (game #1157) - hint #2 - group answers

What are the answers for today's NYT Connections groups?

  • YELLOW: DOOMED
  • GREEN: BASIC CABLE CHANNELS
  • BLUE: WORDS IN AN AUCTIONEER'S CHANT
  • PURPLE: HOMOPHONES OF FACIAL FEATURES

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

NYT Connections today (game #1157) - the answers

NYT Connections answers for game 1157 on a purple background

(Image credit: New York Times)

The answers to today's Connections, game #1157, are…

  • YELLOW: DOOMED: DONE, SUNK, THROUGH, TOAST
  • GREEN: BASIC CABLE CHANNELS: BET, BRAVO, HISTORY, USA
  • BLUE: WORDS IN AN AUCTIONEER'S CHANT: GOING, ONCE, SOLD, TWICE
  • PURPLE: HOMOPHONES OF FACIAL FEATURES: AYE, HARE, KNOWS, TUNG
  • My rating: Easy
  • My score: Perfect

It was very pleasant to see some tiles made up of single words after a run of two-worded tiles, but it didn’t make pouting the four groups together any easier.

That is until I had a blinding moment of revelation and remembered that I had watched the English Premier league on USA Network and BET, BRAVO and HISTORY were also TV stations of note, not that I know them as BASIC CABLE CHANNELS.

From here it all came together like a charm and I wondered why I was ever confused. That, though, is part of the magic that is Connections: bafflement and enlightenment within seconds.

Yesterday's NYT Connections answers (Monday, August 10, 2026, game #1156)

  • YELLOW: HAPHAZARDLY: ANY OLD HOW, AT RANDOM, HELTER-SKELTER, WILLY-NILLY
  • GREEN: WAYS TO RECEIVE EVENT TICKETS: MAIL DELIVERY, MOBILE TICKET, PRINT-AT-HOME, WILL CALL
  • BLUE: SECTIONS ON AN INVOICE: BALANCE DUE, BILL TO, ORDER NUMBER, UNIT PRICE
  • PURPLE: FAMOUS GOATEES: BILLY GOAT, COLONEL SANDERS, DOCTOR STRANGE, THE DEVIL

What is NYT Connections?

NYT Connections is one of several increasingly popular word games made by the New York Times. It challenges you to find groups of four items that share something in common, and each group has a different difficulty level: green is easy, yellow a little harder, blue often quite tough and purple usually very difficult.

On the plus side, you don't technically need to solve the final one, as you'll be able to answer that one by a process of elimination. What's more, you can make up to four mistakes, which gives you a little bit of breathing room.

It's a little more involved than something like Wordle, however, and there are plenty of opportunities for the game to trip you up with tricks. For instance, watch out for homophones and other word games that could disguise the answers.

It's playable for free via the NYT Games site on desktop or mobile.

3D-printed drones built on a US Navy ship for the first time, potentially opening a whole new world of possibilities for future warfare

  • Firestorm Labs printed 12 drones aboard USS Essex during a Pacific voyage
  • More than 1,000 drone components were manufactured directly aboard the warship
  • The Navy tested drone production while waves reached 12 feet

Firestorm Labs has produced 3D-printed drones aboard a US Navy ship at sea, testing manufacturing without conventional shore-based logistics support systems.

The company manufactured more than 1,000 components and assembled 12 Squall first-person-view drones aboard USS Essex during its voyage toward Hawaii waters.

The drones were subsequently flown as opposing aircraft during a counter-drone exercise conducted during the Rim of the Pacific, or RIMPAC, 2026.

Manufacturing drones at sea

Firestorm Labs used its xCell containerized microfactory to manufacture drone components and additional parts while the amphibious assault ship remained underway.

The system functions as a compact production facility designed for Navy vessels, allowing crews to manufacture unmanned aircraft and selected replacement components.

During the trial, service members assembled drones while waves reached 12 feet, providing a demanding environment for onboard manufacturing operations.

Personnel also printed mechanical test components used to assess the effectiveness and performance of the equipment during production aboard the vessel.

The same equipment was used to fabricate military repair parts required by USS Essex personnel during the ship’s Pacific deployment.

“Every part xCell printed on deck is one that doesn’t need to be flown or shipped across contested waters — cutting the fuel, aircraft hours, and personnel it takes to keep a ship operational,” Firestorm Labs said via LinkedIn.

“Repairs that once meant days or weeks waiting on a resupply run can now happen in hours, on station.”

Under the company’s description, repairs requiring conventional supply missions could instead be completed within hours when suitable production capability remains available.

The trial also gives Navy personnel experience operating a manufacturing system while managing shipboard conditions, equipment requirements, and production tasks simultaneously.

A wider move toward containerized military capabilities

The experiment comes as the Navy develops modular capabilities transported inside containers and deployed where conventional infrastructure remains limited during operations.

Chief of Naval Operations Adm. Daryl Caudle announced a containerized capability campaign plan in March during the McAleese Defense Programs conference.

His plan calls for transportable containers carrying capabilities such as drones and weapons to be deployed across different operational regions.

The Pentagon has separately pursued containerized munitions, with framework agreements announced in May involving Anduril, CoAspire, Leidos, and Zone 5.

Those agreements cover more than 10,000 containerized missiles scheduled for acquisition over three years beginning in 2027 under the program.

The Navy’s onboard drone production test combines this containerized approach with additive manufacturing conducted directly from an operating warship.

For crews operating far from established bases, such production could provide another method for obtaining selected drones and replacement components when needed.

However, the trial does not establish how reliably the system can sustain production during prolonged operations or under more demanding combat conditions.

Its practical value will depend on whether the equipment can consistently produce dependable aircraft and parts at useful rates during extended deployments.

Via Defense News

Google logo on a black background next to text reading 'Click to follow TechRadar'

'It's Stalin's dream' — Quote of the day by software pioneer Richard Stallman on the tracking capabilities of cell phones

The programmer Richard Stallman is not a household name, but his work has been instrumental in building the software industry, as has his long-term campaign for free software. He's also been a huge advocate for privacy in the digital age, and has railed against the rise of cell phones for that reason.

Who needs phones anyway?

Stallman first disclosed his views on cell phones in an interview with Network World, during a time in which smartphones were exploding in popularity.

Quote of the day

This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. Read the full series here.

During this interview, Stallman indicated his long-held belief that the portable phones that many millions use would be the perfect tool that authoritarian forces could exploit and use to track the movements of populations.

He also advocated for free software, which you would expect from the founder of the Free Software Foundation (FSF), which he established in 1985. This was backed by the creation of the GNU project – a free software, mass collaboration movement to give users freedom of choice to use and develop software for their devices.

The legacy of free software

Despite his reluctance to ever use a cell phone, one of Stallman's achievements – which he himself acknowledged in the interview – was the third-party version of the Android mobile OS, from which all proprietary software was stripped out.

He pointed to new systems like Replicant, an alternative version of Android, that can run on certain devices without additional proprietary software. The catch is that this only works with older and outdated handsets, like the Samsung Galaxy S3 or the Galaxy Note 2.

I asked Gemini if my chicken salad was still good: it saved itself and my stomach

What is AI good for? It's a question I get asked and ask myself almost every day. Unlike a wrench, hammer, or screwdriver, which are each good for one or two tasks, AI is amorphous and intimidating in its breadth. It seems capable of almost anything, especially as it changes and grows more intelligent. People pump it up as a do-it-all wonder, and yet, the question remains: what would I do with it?

Often, I find the answer to that question in the moment. For instance, as a partially color-blind person, I struggle to match clothing. Now, I often ask Gemini. I'll take my iPhone 17 Pro Max, open Gemini, turn on Gemini Live, pick out a shirt or pants (or both), and ask if they go together or which option is best. I always get an answer and, honestly, I usually follow the uncomplicated AI-generated advice.

Success in one area of your life with technology usually leads you to try it in another, especially with the ever-fungible AI.

In my house, I'm known as the risk taker, at least when it comes to food. "Best by" is a suggestion. "Use before,' is friendly advice. My family often blanches at my aged food consumption habits. Yes, I'll eat that five-day-old steak. Those English Muffins expired two weeks ago? Slide them over.

Enter the risk-taker

I know, it's not great, and when it was lunchtime this weekend I slid the week-plus-old store-bought-and-made chicken salad from the fridge and considered making a sandwich.

Staring at the "made on" date as if my gaze might rearrange the figures, I realized that I might be taking a risk. So I opened the container and sniffed the still spry-looking salad. It's at moments like this that I wonder, "What am I doing? Does my nose really know the difference between safe and stale or, more importantly, safe and decidedly turned?" I can tell you with some confidence: it does not.

Still, having grown up in a house where money was tight and you rarely threw anything away, I was hesitant to dump this half-a-pound of chicken salad (slightly turned or not).

I stood there in my kitchen for a minute, weighing my options and thinking that slightly sour chicken salad might not, with the right toast, be that bad.

Then I looked at my phone, lying face down on the counter, but surely judging me.

I would ask Gemini.

Putting Gemini on the menu

After launching the app, I turned on Gemini Live and pointed the camera at the open container. "Hey, this chicken salad was made on 8/1. Do you think it's still good?" I asked hopefully.

Gemini thought for a moment and then responded, but not in the way I expected.

Before giving me the answer, Gemini launched into what sounded a bit like one of those disclaimers for an Ozempic TV commercial:

"This information is not intended to be a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your physician or other qualified health provider with any questions you may have regarding a medical condition."

Clearly, I struck a nerve. I only asked about the chicken salad, not if I should have a kidney removed.

I get it. If I'd asked this question a couple of years ago, Gemini might've launched right into an analysis, but concerns about AI accuracy and understanding of human needs and context have risen since the emergence of generative AI. Sure, it's way smarter and less likely to give you false or hallucinated information, but it's also, well, not a doctor or even a dietician.

A recent Gallup poll found that more than 25% of Americans are using AI for health info or advice, and of them, more than half query AI for health-related advice and analysis before visiting a doctor. The problem is that AI is not a medical professional, and while it can dig through the billions of health- and medical-related bits stored online, it doesn't have a medical license. It can't understand or treat your various maladies.

In my case, though, Gemini drew a long thin line from my seemingly innocuous question about chicken salad freshness to a potentially incorrect answer, my possible gastric emergency, and a potential lawsuit against Google and Gemini brought on my behalf by my surviving family members.

Look, food poisoning isn't usually fatal, at least according to Healthline, but it is yucky and uncomfortable. I think Gemini was just trying to avoid me taking its word as law on this topic and a potentially bad outcome for both of us.

I'm still hungry

But what about eating this rapidly warming chicken salad?

After the voluminous disclaimer, Gemini got to the heart of the matter:

"According to food safety guidelines, chicken salad should be stored in the refrigerator for only three to four days. Since this chicken salad was made on August 1st and today is August 9th, it is no longer safe to eat and should be discarded."

The answer, based less on the looks of this chicken salad and more on general advice that I often ignore, ultimately had the desired result.

You and my family will be pleased to know I took Gemini's advice, threw out the chicken salad, and made myself a peanut butter and jelly sandwich.

Naturally, I asked Gemini's opinion:

"Yes, absolutely! A PB&J is a much better and safer option right now.

Peanut butter and jelly have a significantly longer shelf life and aren't prone to the rapid bacterial growth that affects meat-based, mayonnaise-heavy dishes like chicken salad. It's a classic, risk-free, and delicious backup plan. Enjoy your lunch!"

Fine. Thanks, Gemini, and bon-appétit.

The US government wants to make it easier to build and launch floating nuclear reactors, 'unleashing American energy dominance'

  • Washington wants new rules for civilian nuclear reactors operating at sea
  • IAEA will launch ATLAS as America pushes nuclear power offshore
  • Small modular reactors could power ships without frequent nuclear refueling

The United States government is backing an international effort to clear regulatory barriers around civilian nuclear reactors operating on ships and floating platforms.

The initiative could eventually enable floating power plants serving coastal communities and industries requiring substantial electricity or desalination capacity.

The International Atomic Energy Agency (IAEA) will launch its Atomic Technologies Licensed for Applications at Sea (ATLAS) initiative in Washington on August 26 and 27, aiming to clear the path for reactors at sea.

US pushes for nuclear power at sea

"The global maritime sector is at a critical turning point, facing urgent pressure to sustain long-distance, high-speed operations while ensuring reliability and energy security," said Rafael Mariano Grossi, Director General of the IAEA.

"Small modular reactors offer a safe and viable option for maritime transport and offshore energy systems, delivering high energy density and long operating cycles that eliminate the need for frequent refueling."

Ahead of the official ATLAS launch, the United States will hold an Industry Day event on August 25 to showcase relevant technology.

American nuclear and maritime companies are expected to attend, each hoping to secure a share of any emerging global market.

US Secretary of Energy Chris Wright tied the event to the Department of Energy's wider push for more atomic power.

"DoE remains focused on unleashing American energy dominance, accelerating innovation, and advancing sources of energy that are affordable, reliable, and secure for the American people," Wright said.

Floating reactors carry old and new risks

The Department of Energy is counting on small modular reactors, whose high energy density and long operating cycles could suit ships and offshore installations.

Nuclear-powered vessels are not new to America, since every active US Navy aircraft carrier already runs on atomic propulsion today.

The Navy once operated nuclear-powered cruisers as well, including the Virginia class, before retiring them for being too costly to run.

Civilian nuclear ships also have precedent, since the NS Savannah became the first nuclear-powered merchant vessel when it launched in 1959.

That vessel proved too expensive to operate, a challenge small modular reactors (SMR) advocates now hope newer reactor designs can finally overcome.

Russia currently operates the world's only floating nuclear power plant, the Akademik Lomonosov, which first launched back in August 2019.

Its two KLT-40S reactors can generate a combined 70 MW of electricity, enough to serve remote coastal communities and light industry.

Placing a reactor on water changes the associated risks rather than eliminating them, since remote platforms may lack backup power.

The surrounding sea can serve as a vast heat sink for cooling, though emergency access could prove more difficult offshore.

Any accident could also risk radioactive contamination of nearby marine environments, endangering the very coastal community the reactor intended to serve.

The push toward floating and shipborne reactors suggests nuclear power is being reconsidered as a serious option for maritime and offshore energy needs.

Whether SMR technology can finally make such projects economical, after decades of costly false starts, remains to be seen.

Via The Register

Google logo on a black background next to text reading 'Click to follow TechRadar'

❌