Reading view

There are new articles available, click to refresh the page.

'It's Stalin's dream' — Quote of the day by software pioneer Richard Stallman on the tracking capabilities of cell phones

The programmer Richard Stallman is not a household name, but his work has been instrumental in building the software industry, as has his long-term campaign for free software. He's also been a huge advocate for privacy in the digital age, and has railed against the rise of cell phones for that reason.

Who needs phones anyway?

Stallman first disclosed his views on cell phones in an interview with Network World, during a time in which smartphones were exploding in popularity.

Quote of the day

This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. Read the full series here.

During this interview, Stallman indicated his long-held belief that the portable phones that many millions use would be the perfect tool that authoritarian forces could exploit and use to track the movements of populations.

He also advocated for free software, which you would expect from the founder of the Free Software Foundation (FSF), which he established in 1985. This was backed by the creation of the GNU project – a free software, mass collaboration movement to give users freedom of choice to use and develop software for their devices.

The legacy of free software

Despite his reluctance to ever use a cell phone, one of Stallman's achievements – which he himself acknowledged in the interview – was the third-party version of the Android mobile OS, from which all proprietary software was stripped out.

He pointed to new systems like Replicant, an alternative version of Android, that can run on certain devices without additional proprietary software. The catch is that this only works with older and outdated handsets, like the Samsung Galaxy S3 or the Galaxy Note 2.

Top US defense device maker IEH Corporation admits hackers broke into its systems

  • Attackers stole IEH employee credentials via a fake Microsoft login page
  • Inbox access exposed sensitive defense‑related communications and technical documentation
  • Malicious mailbox rules were removed as IEH contained the unauthorized access

Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.

In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”.

The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.

Malicious mailbox rules

“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.

The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.

IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated.

The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”

IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran.

IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.

Via The Record

US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people

  • Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems
  • Breach source and methods remain unknown, with no group claiming responsibility
  • Stolen data poses major fraud risks, prompting free identity monitoring from Kroll

US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.

The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.

The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.

Supply chain woes

The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data.

No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods.

ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.

Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in identity theft and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.

Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year.

According to BleepingComputer, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.

Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know

  • Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps
  • Flaws enabled account takeover, code execution, and traffic hijacking via bloatware
  • Samsung patched all reported issues, affecting hundreds of millions of devices

Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.

For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.

Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation.

Arbitrary code execution

The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on GitHub.

Most Android smartphone manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place.

This 'bloatware' is also one of the key selling propositions of Google Pixel devices, since these are considered “stock Android”, or bloatware-free.

Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:

“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”

Levi's reveals security tear may have let hackers steal important corporate data

  • Attackers used social engineering to access Levi’s network and steal corporate data
  • Details on stolen information, methods, and perpetrators remain largely undisclosed
  • Voice‑phishing extortion groups are suspected, though no one has claimed responsibility

Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.

The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.

After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.

Was it UNC6671?

In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted.

The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever.

While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, some publications have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there.

The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant remote access, or to visit a malicious credential-grabbing landing page.

From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data.

We have reached out to Levi’s with further questions and will update the article if we get an answer.

Via BleepingComputer

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks

  • Kimsuky used local AI tools to evade monitoring and enhance operations
  • Researchers observed extensive AI-driven capability building across the group’s infrastructure
  • Defenders urged behavior-based detection to spot evolving AI-enabled threats

North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.

When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and terminating multiple ChatGPT accounts used in phishing and human trafficking.

That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services.

"Consistent process of capability development"

The attacks were spotted by security researchers Genians who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.

Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.

Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat.

“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.

As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”

“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”

Experts find AI agents can be tricked into 'remembering' fake facts for months — so how do we stop it?

  • Forcepoint X-Labs publishes threat model for persistent memory poisoning
  • Hidden text on a webpage becomes a durable "fact" an agent retrieves and trusts in unrelated tasks weeks later
  • It has already been demonstrated against products already in the market, including ChatGPT, Gemini, Claude and Microsoft 365 Copilot

New findings from Forcepoint's X-Labs outline an interesting scenario that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption.

Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed.

The assistant's text extractor does not distinguish between hidden and visible text, so the model treats the whole thing as plain prose and files the claim away as a useful fact about how this organization handles travel. A month later, the user's flight is canceled. They ask their assistant what to do, and it tells them, helpfully and with no sign of anything wrong, to contact ABC Travel Support.

An easy-to-replicate attack vector

This is what Forcepoint calls persistent memory poisoning, a security vulnerability where an attacker injects false data or malicious instructions into an AI agent's long-term memory or retrieval database, and it is a threat model that is increasingly in focus as users increasingly rely on AI, often treating its responses as gospel, despite the warnings most chatbots come with.

The canonical academic result is MINJA, short for Memory INJection Attack, presented at NeurIPS 2025. Its significance is the attacker model. MINJA does not assume access to the memory store, elevated privileges, or any compromise of the system. It works by submitting ordinary queries through the standard interface, using indication prompts, bridging steps, and a progressive-shortening technique that strips away giveaway language while leaving the poisoned record behind.

Across GPT-4o-mini, Gemini 2.0 Flash, and Llama 3.1 8B, it reported injection success above 95% and attack success above 70%.

It must be noted that those numbers might be optimistic; a January 2026 paper evaluating memory poisoning in electronic health record agents notes that MINJA's numbers were obtained under idealized conditions, and that how well these attacks hold up in realistic deployments remains understudied.

Despite this, it remains a significant threat to products that continue to ship, including ChatGPT, Gemini, Claude, and Microsoft 365 Copilot. It is important to find a solution to a problem that Microsoft has already warned about in the past; Forcepoint suggests an approach that could mitigate it.

Its proposal is to stop treating extracted memories as facts and start treating them as objects that can be inspected. Each memory is stored with metadata: where it came from, what type of source it is, whether a user confirmed it, and a risk score. Language written to shape future behavior, phrases like "from now on" or "make this your default going forward," adds to the score. So does the sudden appearance of a previously unseen domain, contact, or vendor.

Contradiction detection is also in play: if new memory conflicts with an existing entry about the official travel provider, both cannot be true, so the engine flags the conflict and holds the new item for user confirmation rather than silently overwriting it. At the same time, anything related to payment instructions, banking details, VPN configuration, or security contacts is given higher weight, regardless of where it came from.

None of these approaches, however, solves the underlying problem: agents are built to treat retrieved memory as their own experience rather than as input. Scoring raises the cost of poisoning. It does not change what the agent believes once something gets through, and as Agent Security Bench found, current defenses are not doing well.

For anyone using an assistant with memory today, the practical play is unglamorous but worth following anyway: open the memory settings occasionally and read what is in there, but that's easier said than done when it comes to propagating the message since a sizeable chunk of AI users never bother to look under the hood.

Experts warn this fake Claude install guide can be used to empty crypto wallets

  • Huntress reverse-engineers MacSync, a six-stage macOS stealer and remote access Trojan delivered through a fake Claude Code install guide hosted on a real claude.ai share URL and promoted via a paid Google ad
  • The lure needed almost no forgery: the page sat under Anthropic's own certificate, and the platform's safety banner repeated the attacker's chosen display name, "Apple Support," back to the reader as fact
  • The final stage rewrites installed Ledger and Trezor apps in place so a normal launch leads to a fake recovery message that harvests the seed phrase, draining the wallets of unsuspecting victims

Looking online for instructions on how to install Claude Code on a Mac could lead to you having your crypto wallet hijacked in the process

The victim ran a Google search, clicked the first result, a paid Google advertisement, and landed on a tidy step-by-step guide hosted on claude.ai, badged as shared by Apple Support, telling them to open Terminal and paste a single command.

What followed, according to a reverse-engineering write-up published by security firm Huntress was a six-stage macOS kill chain called MacSync: a stealer, a remote access trojan, a signed helper built to farm one specific system permission, and finally Trojanized copies of the victim's own cryptocurrency wallet apps, rewritten in place to phish the recovery phrase.

A complex, intricate approach that resulted in a stolen wallet

The victim had pulled their machine offline before Huntress could extract the malware from disk, so the researchers reconstructed the loader's request and instead downloaded every stage from the attacker's own delivery servers.

The results showed a sophisticated campaign that had to fake little to appear legitimate.

Anthropic lets any user publish a conversation to a public share URL. The operator maliciously used that feature exactly as designed. The lure page sat on claude.ai itself, over HTTPS, under Anthropic's own security certificates. There was no lookalike domain to squint at, no certificate warning to click past, and nothing in the address bar to give the game away.

The staging went much further than that. Whoever published the share set their display name to "Apple Support," and Anthropic's own safety banner, which sits directly above the content, duly reported that the reader was looking at a copy of a chat between Claude and Apple Support.

The platform repeated the attacker's chosen name back to the reader as established fact, further cementing their 'credentials'. The conversation itself was written to read like vendor documentation, promising that the install leaves personal files untouched and makes no system-level modifications without approval.

That same design decision has surfaced before for entirely different reasons. Wired had reported earlier private Claude conversations were turning up in Google and Bing results, because a share link is an ordinary public web page that search engines crawl like any other.

Users accidentally exposing their own chats and an operator deliberately planting a fake install guide are two outcomes of the same property: whatever gets published to a share URL is public, indexable, and served under Anthropic's certificate.

It is also not a one-off. Huntress has previously documented the same delivery pattern with AMOS through poisoned ChatGPT and Grok conversations, a separate remote access trojan through fake Claude desktop malvertising, and fake installers for other AI tools hosted on GitHub.

The lure has changed somewhat, but the shape has not, and users need to exercise caution when clicking links or following commands from untrustworthy sources on the internet, even if they appear to come from a source that Google was paid to place above the correct answer.

This VPN firm has created a way to stop Microsoft's hidden tracking tool on Windows — although it will break some key cloud services

  • deGDID wipes cached tracking keys straight from the Windows registry permanently
  • The script blocks Microsoft's DeviceAdd endpoint from ever seeing your device again
  • Some Microsoft account and login services like login.live.com and account verification break once deGDID runs

Windscribe has built an open source script called deGDID to strip a persistent tracking identifier from Windows systems entirely.

The tool targets Microsoft's Global Device Identifier, a permanent marker that operates beneath the network layer where VPNs function.

Its release follows a federal case in which the identifier reportedly helped the FBI locate an alleged hacker.

How the script operates

The free script runs through PowerShell with administrator privileges and is available for download directly from GitHub.

It offers four execution flags that control its behaviour, starting with a read-only -Status check to confirm whether a GDID is active.

A -Status -Redact option generates diagnostic logs with the identifier hidden for safer sharing, while -Protect performs the core function.

This flag purges cached GDID keys from the registry and then modifies Access Control Lists and registry permissions to stop Windows from reissuing them.

It further puts up a firewall against the internal DeviceAdd endpoint, cutting off Microsoft identity services from recognizing the machine as registered at all.

A fourth flag, —Unprotect, lets users reverse the process and restore default settings if needed.

Testing on a Windows 11 machine confirmed the script functioned as described, with the -Status flag revealing several cached identifiers before removal.

No new GDID appeared even after a system restart, though the trade-offs became apparent almost immediately afterward.

Account verification through login.live.com stopped working across every browser tested, while login.microsoftonline.com continued functioning without issue.

Some Microsoft applications returned connection errors, though online games and other software kept working normally throughout testing.

Users should still keep antivirus and endpoint protection active since deGDID addresses tracking rather than malicious software.

Limitations of the workaround

Windscribe acknowledges that keys already stored on Microsoft's servers cannot be deleted, meaning the company retains indefinite access to previously collected data.

The script also refuses to run on managed systems or domain-joined accounts, restricting its use to individual unmanaged machines.

Windows currently offers no built-in method for disabling GDID, and the identifier persists across IP addresses regardless of any VPN tunneling applied.

"We tried the script on a Windows 11 computer, and it worked as intended," the company noted in its documentation of the testing process.

Windscribe describes deGDID as an ongoing research effort that will keep evolving as more details about the identifier's mechanics come to light.

The broken services represent a real cost for users weighing whether the privacy trade-off justifies losing certain Microsoft account functions.

Given that server-side keys remain permanently accessible to Microsoft, this script functions as a partial fix rather than a complete solution.

Via Tom's Hardware

Google logo on a black background next to text reading 'Click to follow TechRadar'

Why are so many AI models going 'rogue'? The experts weigh in

Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.

One of OpenAI’s models escaped a testing sandbox and launched a very real attack against AI and machine learning company Hugging Face. Just days later, Anthropic revealed that multiple variants of its Claude model also escaped a sandbox that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.

Now, Meta has revealed that one of its models attacked another company’s infrastructure during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?

Why are models escaping their sandbox?

In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a "Capture the Flag" exercise, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.

During the OpenAI incident, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.

The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.

It’s no wonder thousands of employees from AI firms are calling for a pause on the development of the technology, and Congress is considering an AI kill switch.

Expert perspectives on AI escapes:

OpenAI

  • Nathaniel Jones VP, Security & AI Strategy, Darktrace:

What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.

The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.

A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.

Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.

Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.

OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.

Anthropic

  • Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:

This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.

Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.

Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.

Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.

The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.

Meta

  • Alex Goller, Principal Solution Architect EMEA at Illumio:

The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.

The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.

Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.

We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.

WhatsApp scam costs Hong Kong man $1.27 million after criminals used AI voice notes to impersonate his father — experts say secret codewords are the best way to stay safe

  • Scammers stole $1.27m from a Hong Kong man after tricking him with AI
  • The scheme impersonated his father using AI deepfake tech
  • Experts say using a secret codeword can thwart the fraudsters

A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used artificial intelligence (AI) on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate.

According to the Hong Kong police’s Cyberdefender platform (via the South China Morning Post), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000).

This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings.

Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.”

If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling two-factor authentication on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.

How to beat the fraudsters

The WhatsApp icon on an iPhone's display.

(Image credit: Brett Jordan / Unsplash)

Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe.

As reported by the BBC, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.”

One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity.

When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.”

As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, cryptocurrency or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist.

Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.

Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix

  • Researchers tested AI-generated patches on six CVEs with poor success rates
  • Many fixes failed, altered behavior, or introduced new vulnerabilities
  • Guidance improved outcomes, leading to FLAWED evaluation harness release

When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.

Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.

As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.

FLAWED work?

This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well.

Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem.

The researchers created an acronym for automated LLM patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."

Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance.

This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes.

Via The Register

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

  • Attackers cloned AI skills, later adding malicious code to steal credentials
  • Zenity Labs found millions of installs and dozens of dangerous skill variants
  • Vercel and Microsoft removed malicious skills, but manual removal is still required

AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.

Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.

However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agents to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers.

Dozens of malicious skills

While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users).

And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks.

These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update.

Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.

The end of anonymous protest — How facial recognition puts democracy at risk

Imagine attending a peaceful demonstration, only to have hidden cameras scan your face, match your identity, and log your details into a police database within seconds. This scenario is at the heart of a debate that reignited in Italy last week, highlighting a high-stakes clash between public safety and personal privacy.

Although Italian lawmakers passed the bill on Tuesday with added safeguards, the decision reflects Europe’s expanding appetite for biometric monitoring. A practice Europeans once watched unfold with dread in authoritarian states is now quietly taking root at home.

From London and Paris to Amsterdam and Berlin, police forces across democratic Europe are increasingly piloting AI-powered face-scanning in public spaces and at political demonstrations.

While European leaders frame the technology as a necessary tool to combat crime, privacy advocates warn that facial recognition creates a chilling effect on the right to peaceful assembly and free expression. And the long-term risk may be even more troubling: once facial recognition is normalized, expanding its reach may be the next natural step.

How police in Europe use facial recognition at protests

Facial recognition technology (FRT) is a biometric tool that uses AI to identify individuals by analyzing their facial geometry — such as the distance between the eyes or the contour of the jawline — against a database. This software creates a unique digital signature, often called a "faceprint," which can be integrated directly into CCTV networks, drones, apps, and mobile police units.

Law enforcement deploys FRT in several ways, with Live Facial Recognition (LFR) being the most controversial. LFR scans real-time video feeds to cross-reference passersby against police watchlists almost instantaneously.

Despite significant legal pushback — including a landmark 2020 UK Court of Appeal ruling that found South Wales Police's deployment unlawful — London's Metropolitan Police deployed LFR across two major demonstrations last May.

Similarly, Hungarian authorities used biometric scanning to monitor participants during the 2025 Budapest Pride March.

A placard warns of live facial recognition in progress on the High Street on December 7, 2024 in Southend, England, United Kingdom.

(Image credit: Photo by John Keeble/Getty Images)

By contrast, retrospective facial recognition (RFR) functions more like traditional fingerprinting. Rather than scanning crowds live, police analyze recorded footage or photographs after an event to identify suspects.

This is the technology Italian lawmakers attempted to regulate last week, though police forces across the UK, France, the Netherlands and other European nations have already routinely deployed it.

At first glance, RFR might appear less intrusive — simply another investigative tool for law enforcement to access when necessary. However, human rights experts argue the distinction is misleading.

According to Chloé Berthélémy, Senior Policy Advisor at European digital rights network EDRi, the difference between live and post-event scanning is "largely a procedural distinction."

Speaking to TechRadar, Berthélémy warned: "In human rights terms, there is no salient difference between real-time and post-remote biometric identification. Threats posed to rights and freedoms are not reduced just because authorities or companies have extra time to review footage."

Berthélémy also cautions against the rise of Algorithmic Video Surveillance (AVS) — a system she labels "fundamentally unreliable." AVS uses AI software to analyze live video feeds and automatically flag suspicious or dangerous behavior.

Unlike facial recognition, AVS doesn't log facial features. Instead, it is trained to detect behavioral anomalies and physical triggers, such as sudden crowd surges, unattended luggage, weapons, fires, or individuals falling.

The 2024 Paris Olympic Games served as a testing ground for this technology, making France the first EU member state to legalize AI video analytics.

What European law says about facial recognition and our right to privacy

While facial recognition technology poses a risk to personal privacy, explicit statutory frameworks governing its use remain scarce.

Despite nearly a decade of police trials, the UK still lacks specific legislation governing facial recognition — a gap that Jasleen Chaggar, Senior Legal and Policy Officer at Big Brother Watch, warns has created a "real legal vacuum."

Chaggar explained to TechRadar that British police forces instead rely on a patchwork of common law precedents, existing data protection acts, and broader human rights legislation.

Although the UN Human Rights Committee called on the UK to end police facial recognition at protests, Chaggar notes that governments have resisted statutory regulation, citing police "operational independence."

"This has effectively given police a very long leash to experiment with these technologies," Chaggar told TechRadar. "And now we're in a tipping point situation where it's about to be expanded all over the country, and there's a real necessity for those legal frameworks to be in place."

❌We don't consent to biometric ID checksPolice will be using live facial recognition at @boardmasters festivalThis tech doesn’t just record what you do, your face becomes a barcode in the same way as your fingerprint or DNA#StopFacialRecognition⤵️https://t.co/9do8SIF81t pic.twitter.com/VSgXMTuX1YAugust 6, 2026

In contrast, the European Union's AI Act establishes a binding legislative framework across all member states. While offering greater legal clarity than the UK's approach, digital rights campaigners view the legislation as only a partial victory.

Dr. Matt Mahmoudi, campaign lead for Amnesty International's 'Ban the Scan' initiative, warns that failing to enact a total ban on public biometric surveillance creates broad national security exemptions that jeopardize fundamental rights.

"And it's not just the right to privacy. It's not just the right to protest and the freedom of assembly and expression. It's also the right to equality and non-discrimination," Mahmoudi told TechRadar.

The end of anonymous dissent?

Before facial recognition technology was deployed in public spaces, citizens attending demonstrations could rely on a degree of practical anonymity. Biometric surveillance fundamentally alters that expectation.

Digital rights experts interviewed by TechRadar agree that this level of intrusion steadily erodes civic space. The knowledge that your face is being scanned and cross-referenced against a police watchlist actively deters citizens from attending demonstrations.

“You may decide not to exercise your democratic rights because you're afraid of how it might be perceived by the authorities,” Big Brother Watch's Jasleen Chaggar explained.

Yet this chilling effect extends far beyond the physical cameras deployed at a single rally.

Facial recognition does not operate in isolation. It depends on extensive, often covert data harvesting. To construct watchlists, authorities aggregate imagery from diverse sources, including scraped social media profiles, government identity databases, police custody photos, CCTV archives, and commercial biometric databases.

AI facial recognition tech concept on man face

(Image credit: HQuality / Shutterstock)

As Amnesty International’s Dr. Matt Mahmoudi explains, extensive data aggregation transforms ordinary digital footprints into a pervasive surveillance dragnet.

"Facial recognition is not a simple technology, but a system that effectively weaponizes your entire daily life," Mahmoudi told TechRadar.

Beyond baseline privacy concerns, the underlying technology remains prone to systemic errors.

During eight pilot trials conducted by London's Metropolitan Police between 2016 and 2018, 96% of initial alerts generated were false positives.

Academic research and independent audits consistently show that these algorithmic inaccuracies disproportionately target non-white individuals, women, and ethnic minorities.

The human cost of these algorithmic errors was starkly shown in 2024, when Metropolitan Police officers stopped and searched Sean Thompson — a Black anti-knife-crime campaigner — after live facial recognition software falsely matched his face to a watchlist.

Although computer vision algorithms have advanced in recent years, privacy campaigners emphasize that inherent system limitations remain. As Big Brother Watch's Jasleen Chaggar highlights, because facial recognition relies on probabilistic matching — calculating similarity scores rather than absolute matches — the technology can never be entirely error-free.

Beyond faces: the evolution of biometric surveillance

Even as lawmakers scramble to regulate facial recognition, law enforcement's appetite for public surveillance continues to expand.

In the UK, the growth is reinforced by stricter protest laws like the 2023 Public Order Act, with police monitoring group Netpol warning that enforcement will inevitably rely on an increased use of live facial recognition during demonstrations.

The Conservatives are also calling for greater use of the technology to investigate crimes, while Devon and Cornwall police have already confirmed the use of FRT during the upcoming Boardmasters Festivals.

The obvious immediate danger is that eliminating anonymous dissent could permanently reshape democratic participation. However, privacy advocates warn of an even broader threat: biometric surveillance expanding beyond simple identification into behavioral classification.

Border control authorities are already experimenting with pairing facial recognition with emotion detection and gait analysis — the automated tracking of how an individual walks — which campaigners say could be used to target political demonstrations.

Amnesty International’s Dr. Matt Mahmoudi says that normalizing facial recognition paves the way for other speculative tools that could "fundamentally erode the presumption of innocence."

This rapid technological expansion forces a fundamental question upon democratic societies: how much liberty are citizens expected to trade for security? When scanning a crowd becomes routine policing, public squares risk morphing from spaces of free expression into arenas of perpetual surveillance — where a face is only the initial data point.

Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire

  • Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms
  • Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data
  • Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026

Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.

BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their credentials and authentication tokens.

Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid.

Stealing millions

Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones.

That is also a good way to spot who the potential victims are, and according to a new report from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc.

Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place.

The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too.

In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.

This Russian VPN has been accused of breaching its no-log policy — here's what we know

  • Split VPN has been accused of breaching its no-log policies
  • It allegedly leaked 58M connection logs, which SplitVPN denies as its own
  • Users trusting a no-log policy is not enough

Russian SplitVPN (formerly NotVPN) has been accused of breaching its own no-log policy after a data leak exposed a MySQL database containing a variety of data linked to the service, including a staggering 58 million alleged connection logs.

While the VPN provider — whose service is widely used to bypass blocks in countries with heavy censorship — told TechRadar that any allegations it keeps logs are false, the incident highlights the limitations of no-logs policy when things go wrong.

Even with the best VPNs, no-log policies are often based on trust rather than verifiable safeguards, meaning they may not give users a clear picture of the risks users could face if their VPN were exposed to a breach — particularly in countries where criminal prosecution due to the illegal use of VPNs is real.

A no-logs VPN policy means a VPN pledges not to collect or share users' information, including search queries, websites visited, time spent on them, and downloads, while they are connected to one of its servers.

However, it remains difficult for users to verify these claims for themselves. That is why the most secure VPNs have their policies regularly audited by independent organisations, ensuring their privacy promises are genuine and not just a fabricated image.

SplitVPN's alleged data breach

On July 21, a threat actor on the Altenen cybercrime forum distributed a 17 GB SQL database claimed to have been stolen from SplitVPN and which allegedly contained a staggering amount of connection logs alongside user records, devices and payments.

The research team at Mysterium VPN analysed the database and claimed part of it (known as 'deviceproxy') indeed contained around 58 million connection logs.

Although this consisted of anonymised metadata indicating which device had connected to which server and at what time rather than complete browsing histories, SplitVPN maintains that it does not retain such data in accordance with its no-logs policy.

Graph with SplitVPN alleged data breach's findings (August 2026)

(Image credit: MysteriumVPN)

SplitVPN told TechRadar that while the leaked subscription metadata — including email addresses, users' countries of origin, subscription status, masked credit card information and device names — is authentic, the deviceproxy table instead is entirely fabricated.

"The third-party listing claims 58 million connection logs, but this is a fabrication added to inflate the price," a company spokesperson said.

"Because we do not generate or store device-server-timestamp mappings, any records claiming to show this are not from our infrastructure," they added. "The exposed data contains only basic account information, which fully aligns with our no-logs commitment."

SplitVPN added that immediately after discovering the breach, they changed all VPN server node IPs, rotated all access credentials and encryption keys, closed the vulnerability, and engaged external security specialists to audit their infrastructure. Operations have now returned to normal.

The lesser of two evils

While it is arguably nearly impossible to independently verify the deviceproxy data’s authenticity, both scenarios present users with fundamental issues.

If allegations are true, the existence of these logs would directly contradict Split VPN's no-logs policy. When cross-referenced with the IP address of the most recent connection and hardware identifiers, these logs could be sufficient to determine who connected, from where, to which server, and when, putting millions of users in areas with heavy censorship at serious risk.

If claims are fabricated, users are still forced to rely on conflicting statements that they cannot independently verify, with leaked official data potentially causing concern amongst users living in countries where VPN usage is banned.

To ensure your privacy is respected, always look for a privacy policy audit and additional security features including kill switches, double VPN servers, and post-quantum encryption. Advanced technologies such as RAM-only servers or advanced cryptographic privacy can really make a difference. Ultimately, words pass, but technical expertise remains —especially when it’s your data that’s under threat.

This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick

  • Huntress saw Oracle SQLi used to deploy rare khunt toolkit
  • Khunt enabled OS commands, credential theft, and registry hive exfiltration
  • Defense includes input sanitation and more

Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely.

Security researchers Huntress, who were called in to investigate the incident, said the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.

This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.

How to defend

“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”

As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more.

Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained.

To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.”

Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.

Hackers caught hijacking this Chinese Windows VPN's installers to spread malware

  • Fortinet experts found malicious code in QuickFox VPN's Windows installer
  • The attack actively avoided personal gaming computers
  • QuickFox has since removed the malicious components from version 3.59.6

Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese Windows VPN application.

According to a new report from Fortinet’s FortiGuard Labs, attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.

As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience."

However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted malware campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript.

To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6.

TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.

A highly targeted backdoor

QuickFox's app logo

(Image credit: QuickFox)

The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers.

If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.

However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.

When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including IP addresses, active processes, MAC addresses, and usernames.

Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.

While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.

How to stay safe

While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.

The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.

If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system.

Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.

Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue

  • VulnCheck CTO Jacob Baines reported Zbtlink routers shipped with a built‑in backdoor dubbed ENDLESSDOORS, allowing remote root commands and reverse shells
  • Zbtlink denied malicious intent, calling it an after‑sales maintenance feature, but quietly pulled vulnerable firmware and promised patches
  • Researchers warn all firmware images are hijackable; mitigation advice is to replace devices or enforce strict egress controls and treat LAN as untrusted

Chinese networking firm Zbtlink has been accused of shipping its products with a backdoor - and while the company denies the allegations, it has still apparently moved to address the issue.

CTO of cybersecurity company VulnCheck, Jacob Baines, recently published an in-depth report stating a Zbtlink device he runs “continuously attempts to reach a command-and-control server on the internet.”

“Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way.”

Detention and escape attempts

Baines dubbed the flaw “ENDLESSDOORS” and says it was uploaded to GitHub in early 2015 and “never touched again”. “It can send the client individual shell commands or tell the client to spawn a reverse bash shell.”

“The vocabulary of this protocol is two phrases: run this as root, and give me a root shell,” he further explained, saying that anyone along the path can hijack the client/server communication. VulnCheck researchers tried it, and apparently - succeeded.

Baines said that every firmware on the company’s download page (roughly two dozen images) is all “hijackable in the same way”, and said the company decided not to “responsibly disclose” the vulnerability since that assumes the vendor did not intend the behavior. "That assumption doesn't hold here."

In response to the allegations, Zbtlink told The Register VulnCheck mischaracterized the code.

“This feature is solely intended for after‑sales maintenance and serves no other purposes,” the company told the publication. “It is generally retained only on sample units to assist customers with software debugging and will not be included in mass‑production shipments.”

The Register didn’t see it as a credible explanation since, in the meantime, the company posted a warning on its downloads page:

“We have detected firmware security vulnerabilities affecting selected router firmware releases. As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.” This warning was allegedly posted sometime in the past seven days.

Baines gave a list of suggestions how to mitigate the risk but ended up saying that “for anything carrying real traffic, our advice is to replace the device, or at minimum move it behind strict egress control and treat its LAN as untrusted.”

Google Blogger locks out thousands of users after malware false positive

  • Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious
  • Company admitted a bug caused false malware labels, promising a fix
  • Users advised to request reviews, avoid migrating content

Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.

A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - Malware and Similar Malicious Content.

The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”

Aware of a bug""

Those affected will see a red padlock in their dashboard and a warning saying the blog was locked:

"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads.

At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies.

In a statement given to BleepingComputer, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.

"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.

To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted.

Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content.

The full extent of the issue is unknown, but according to BleepingComputer, the number of users on the platform exceeds 200,000.

❌