Bitdefender says fake pirated downloads of The Odyssey, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware
Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt
These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident
With The Odyssey set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.
What they were actually downloading, according to Bitdefender, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).
The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips.
A regular occurrence for pirates
The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around Mission: Impossible – The Final Reckoning, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.
The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.
Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.
Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.
Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.
It has often been highlighted as one of the most prolific MaaS options out there and has had Microsoft, the DOJ, and the FBI act directly against it in the past, but has managed to stay alive since, evolving into a more stealthy entity.
Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms.
Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.
Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out.
For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.
Proton is seeking a software engineer to help build a "privacy-first browser"
News that it may be based on Google's Chromium disappoints some users
Early community reaction has been surprisingly hostile overall
For many users, the quest to cut Google out of your digital life starts with switching to privacy-first alternatives. Swiss tech firm Proton, famous for its secure email platform and one of the best VPN services on the market, has been leading that charge. Now, it looks like the company might be preparing to take aim at Google Chrome.
According to a newly discovered job listing — first reported by TechCentral.ie — Proton is actively recruiting a software engineer to help build a web browser. The application explicitly mentions joining a "browser product team" based in Geneva or Zurich.
While a dedicated browser might seem like a natural next step for Proton's expanding security-first ecosystem, the initial reaction from its most loyal users has been largely negative.
TechRadar approached Proton for comments, but the company declined to comment.
A Chromium fork or an exploratory project?
The job spec leaves little doubt about the technical foundations of the project. Proton is seeking candidates with "hands-on experience building or maintaining a Chromium-based browser."
The successful engineer will be tasked with implementing "anti-fingerprinting measures, content blocking, or reducing telemetry and third-party dependencies." They will also collaborate to build a "privacy-first internet browser used by millions around the world" across macOS, Windows, and Linux.
Despite these concrete details, it's important not to exaggerate the evidence. Much like when Proton Mail landed on desktop, complex software development takes time.
A single job listing indicates that Proton is experimenting with a browser, but the project could easily remain an internal test for years, or be scrapped altogether before seeing the light of day.
The evidence suggests the company is only just exploring the concept, in fact, with no official plans to ship a finished product anytime soon. So, if you're eager to ditch Google browsing for a secure alternative made by Proton specifically, you might need to wait.
Usually, the announcement of a new privacy tool is met with excitement, but the response on Reddit has been decidedly hostile.
The backlash stems from two main issues: the choice of browser engine and the company's current product roadmap.
First, privacy-conscious users are frustrated by the reliance on Chromium, the open-source codebase maintained by Google.
As one user pointed out, releasing another Chromium-based browser is "indirectly driving us deeper into a monopoly."
Many fans argued that Proton should instead build a Firefox fork or focus its resources on Ladybird, an independent browser project that Proton already officially sponsors.
Second, users feel that Proton is spreading its development resources too thin. Following the recent launch of a full Proton workspace and privacy-first AI chatbot (Lumo), the product ecosystem is growing rapidly.
So, instead of building a web browser from scratch, the community is begging the company to fix existing bugs and deliver long-promised features to its current lineup.
"Proton needs to stop spreading resources and concentrate on core services," wrote one frustrated user. Another added: "How about a good working calendar?"
Whether Proton pushes forward with its Chromium browser or listens to its community's pleas for app updates remains to be seen. For now, the company is keeping its cards close to its chest.
OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work
New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research
Access remains restricted due to dual‑use risks and reduced safeguard operation
OpenAI has announced two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.
Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of AI agents, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.
These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.
What is Daybreak?
To give the cybersecurity community the upper edge, companies like OpenAI started creating dedicated cybersecurity initiatives that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.
Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).
Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.
The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.
Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.
This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.
Complying with "dangerous" requests
Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access.
GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though.
While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own.
Those who wish to be a part of the program directly can do so by applying to join online now.
“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.
“Daybreak Blue and Daybreak Red access are available for approved individuals and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”
The programmer Richard Stallman is not a household name, but his work has been instrumental in building the software industry, as has his long-term campaign for free software. He's also been a huge advocate for privacy in the digital age, and has railed against the rise of cell phones for that reason.
Who needs phones anyway?
Stallman first disclosed his views on cell phones in an interview with Network World, during a time in which smartphones were exploding in popularity.
Quote of the day
This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. Read the full series here.
During this interview, Stallman indicated his long-held belief that the portable phones that many millions use would be the perfect tool that authoritarian forces could exploit and use to track the movements of populations.
He also advocated for free software, which you would expect from the founder of the Free Software Foundation (FSF), which he established in 1985. This was backed by the creation of the GNU project – a free software, mass collaboration movement to give users freedom of choice to use and develop software for their devices.
The legacy of free software
Despite his reluctance to ever use a cell phone, one of Stallman's achievements – which he himself acknowledged in the interview – was the third-party version of the Android mobile OS, from which all proprietary software was stripped out.
He pointed to new systems like Replicant, an alternative version of Android, that can run on certain devices without additional proprietary software. The catch is that this only works with older and outdated handsets, like the Samsung Galaxy S3 or the Galaxy Note 2.
Attackers stole IEH employee credentials via a fake Microsoft login page
Inbox access exposed sensitive defense‑related communications and technical documentation
Malicious mailbox rules were removed as IEH contained the unauthorized access
Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.
In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”.
The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.
Malicious mailbox rules
“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.
The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.
IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated.
The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”
IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran.
IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.
Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems
Breach source and methods remain unknown, with no group claiming responsibility
Stolen data poses major fraud risks, prompting free identity monitoring from Kroll
US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.
The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.
The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.
Supply chain woes
The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data.
No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods.
ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.
Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in identity theft and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.
Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year.
According to BleepingComputer, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.
Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps
Flaws enabled account takeover, code execution, and traffic hijacking via bloatware
Samsung patched all reported issues, affecting hundreds of millions of devices
Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.
For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.
Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation.
Arbitrary code execution
The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on GitHub.
Most Android smartphone manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place.
This 'bloatware' is also one of the key selling propositions of Google Pixel devices, since these are considered “stock Android”, or bloatware-free.
Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:
“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”
Attackers used social engineering to access Levi’s network and steal corporate data
Details on stolen information, methods, and perpetrators remain largely undisclosed
Voice‑phishing extortion groups are suspected, though no one has claimed responsibility
Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.
The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.
After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.
Was it UNC6671?
In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted.
The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever.
While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, some publications have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there.
The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant remote access, or to visit a malicious credential-grabbing landing page.
From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data.
We have reached out to Levi’s with further questions and will update the article if we get an answer.
Kimsuky used local AI tools to evade monitoring and enhance operations
Researchers observed extensive AI-driven capability building across the group’s infrastructure
Defenders urged behavior-based detection to spot evolving AI-enabled threats
North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.
When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and terminating multiple ChatGPT accounts used in phishing and human trafficking.
That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services.
"Consistent process of capability development"
The attacks were spotted by security researchers Genians who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.
Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.
Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat.
“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.
As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”
“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”
Forcepoint X-Labs publishes threat model for persistent memory poisoning
Hidden text on a webpage becomes a durable "fact" an agent retrieves and trusts in unrelated tasks weeks later
It has already been demonstrated against products already in the market, including ChatGPT, Gemini, Claude and Microsoft 365 Copilot
New findings from Forcepoint's X-Labs outline an interesting scenario that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption.
Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed.
The assistant's text extractor does not distinguish between hidden and visible text, so the model treats the whole thing as plain prose and files the claim away as a useful fact about how this organization handles travel. A month later, the user's flight is canceled. They ask their assistant what to do, and it tells them, helpfully and with no sign of anything wrong, to contact ABC Travel Support.
An easy-to-replicate attack vector
This is what Forcepoint calls persistent memory poisoning, a security vulnerability where an attacker injects false data or malicious instructions into an AI agent's long-term memory or retrieval database, and it is a threat model that is increasingly in focus as users increasingly rely on AI, often treating its responses as gospel, despite the warnings most chatbots come with.
The canonical academic result is MINJA, short for Memory INJection Attack, presented at NeurIPS 2025. Its significance is the attacker model. MINJA does not assume access to the memory store, elevated privileges, or any compromise of the system. It works by submitting ordinary queries through the standard interface, using indication prompts, bridging steps, and a progressive-shortening technique that strips away giveaway language while leaving the poisoned record behind.
Across GPT-4o-mini, Gemini 2.0 Flash, and Llama 3.1 8B, it reported injection success above 95% and attack success above 70%.
It must be noted that those numbers might be optimistic; a January 2026 paper evaluating memory poisoning in electronic health record agents notes that MINJA's numbers were obtained under idealized conditions, and that how well these attacks hold up in realistic deployments remains understudied.
Despite this, it remains a significant threat to products that continue to ship, including ChatGPT, Gemini, Claude, and Microsoft 365 Copilot. It is important to find a solution to a problem that Microsoft has already warned about in the past; Forcepoint suggests an approach that could mitigate it.
Its proposal is to stop treating extracted memories as facts and start treating them as objects that can be inspected. Each memory is stored with metadata: where it came from, what type of source it is, whether a user confirmed it, and a risk score. Language written to shape future behavior, phrases like "from now on" or "make this your default going forward," adds to the score. So does the sudden appearance of a previously unseen domain, contact, or vendor.
Contradiction detection is also in play: if new memory conflicts with an existing entry about the official travel provider, both cannot be true, so the engine flags the conflict and holds the new item for user confirmation rather than silently overwriting it. At the same time, anything related to payment instructions, banking details, VPN configuration, or security contacts is given higher weight, regardless of where it came from.
None of these approaches, however, solves the underlying problem: agents are built to treat retrieved memory as their own experience rather than as input. Scoring raises the cost of poisoning. It does not change what the agent believes once something gets through, and as Agent Security Bench found, current defenses are not doing well.
For anyone using an assistant with memory today, the practical play is unglamorous but worth following anyway: open the memory settings occasionally and read what is in there, but that's easier said than done when it comes to propagating the message since a sizeable chunk of AI users never bother to look under the hood.
Huntress reverse-engineers MacSync, a six-stage macOS stealer and remote access Trojan delivered through a fake Claude Code install guide hosted on a real claude.ai share URL and promoted via a paid Google ad
The lure needed almost no forgery: the page sat under Anthropic's own certificate, and the platform's safety banner repeated the attacker's chosen display name, "Apple Support," back to the reader as fact
The final stage rewrites installed Ledger and Trezor apps in place so a normal launch leads to a fake recovery message that harvests the seed phrase, draining the wallets of unsuspecting victims
Looking online for instructions on how to install Claude Code on a Mac could lead to you having your crypto wallet hijacked in the process
The victim ran a Google search, clicked the first result, a paid Google advertisement, and landed on a tidy step-by-step guide hosted on claude.ai, badged as shared by Apple Support, telling them to open Terminal and paste a single command.
What followed, according to a reverse-engineering write-up published by security firm Huntress was a six-stage macOS kill chain called MacSync: a stealer, a remote access trojan, a signed helper built to farm one specific system permission, and finally Trojanized copies of the victim's own cryptocurrency wallet apps, rewritten in place to phish the recovery phrase.
A complex, intricate approach that resulted in a stolen wallet
The victim had pulled their machine offline before Huntress could extract the malware from disk, so the researchers reconstructed the loader's request and instead downloaded every stage from the attacker's own delivery servers.
Anthropic lets any user publish a conversation to a public share URL. The operator maliciously used that feature exactly as designed. The lure page sat on claude.ai itself, over HTTPS, under Anthropic's own security certificates. There was no lookalike domain to squint at, no certificate warning to click past, and nothing in the address bar to give the game away.
The staging went much further than that. Whoever published the share set their display name to "Apple Support," and Anthropic's own safety banner, which sits directly above the content, duly reported that the reader was looking at a copy of a chat between Claude and Apple Support.
The platform repeated the attacker's chosen name back to the reader as established fact, further cementing their 'credentials'. The conversation itself was written to read like vendor documentation, promising that the install leaves personal files untouched and makes no system-level modifications without approval.
That same design decision has surfaced before for entirely different reasons. Wired had reported earlier private Claude conversations were turning up in Google and Bing results, because a share link is an ordinary public web page that search engines crawl like any other.
Users accidentally exposing their own chats and an operator deliberately planting a fake install guide are two outcomes of the same property: whatever gets published to a share URL is public, indexable, and served under Anthropic's certificate.
It is also not a one-off. Huntress has previously documented the same delivery pattern with AMOS through poisoned ChatGPT and Grok conversations, a separate remote access trojan through fake Claude desktop malvertising, and fake installers for other AI tools hosted on GitHub.
The lure has changed somewhat, but the shape has not, and users need to exercise caution when clicking links or following commands from untrustworthy sources on the internet, even if they appear to come from a source that Google was paid to place above the correct answer.
deGDID wipes cached tracking keys straight from the Windows registry permanently
The script blocks Microsoft's DeviceAdd endpoint from ever seeing your device again
Some Microsoft account and login services like login.live.com and account verification break once deGDID runs
Windscribe has built an open source script called deGDID to strip a persistent tracking identifier from Windows systems entirely.
The tool targets Microsoft's Global Device Identifier, a permanent marker that operates beneath the network layer where VPNs function.
Its release follows a federal case in which the identifier reportedly helped the FBI locate an alleged hacker.
How the script operates
The free script runs through PowerShell with administrator privileges and is available for download directly from GitHub.
It offers four execution flags that control its behaviour, starting with a read-only -Status check to confirm whether a GDID is active.
A -Status -Redact option generates diagnostic logs with the identifier hidden for safer sharing, while -Protect performs the core function.
This flag purges cached GDID keys from the registry and then modifies Access Control Lists and registry permissions to stop Windows from reissuing them.
It further puts up a firewall against the internal DeviceAdd endpoint, cutting off Microsoft identity services from recognizing the machine as registered at all.
A fourth flag, —Unprotect, lets users reverse the process and restore default settings if needed.
Testing on a Windows 11 machine confirmed the script functioned as described, with the -Status flag revealing several cached identifiers before removal.
No new GDID appeared even after a system restart, though the trade-offs became apparent almost immediately afterward.
Account verification through login.live.com stopped working across every browser tested, while login.microsoftonline.com continued functioning without issue.
Some Microsoft applications returned connection errors, though online games and other software kept working normally throughout testing.
Users should still keep antivirus and endpoint protection active since deGDID addresses tracking rather than malicious software.
Limitations of the workaround
Windscribe acknowledges that keys already stored on Microsoft's servers cannot be deleted, meaning the company retains indefinite access to previously collected data.
The script also refuses to run on managed systems or domain-joined accounts, restricting its use to individual unmanaged machines.
Windows currently offers no built-in method for disabling GDID, and the identifier persists across IP addresses regardless of any VPN tunneling applied.
"We tried the script on a Windows 11 computer, and it worked as intended," the company noted in its documentation of the testing process.
Windscribe describes deGDID as an ongoing research effort that will keep evolving as more details about the identifier's mechanics come to light.
The broken services represent a real cost for users weighing whether the privacy trade-off justifies losing certain Microsoft account functions.
Given that server-side keys remain permanently accessible to Microsoft, this script functions as a partial fix rather than a complete solution.
Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.
Now, Meta has revealed that one of its models attacked another company’s infrastructure during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?
Why are models escaping their sandbox?
In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a "Capture the Flag" exercise, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.
During the OpenAI incident, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.
The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.
Nathaniel Jones VP, Security & AI Strategy, Darktrace:
What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.
The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.
A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.
Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.
Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.
OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.
Anthropic
Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:
This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.
Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.
Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.
Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.
The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.
Meta
Alex Goller, Principal Solution Architect EMEA at Illumio:
The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.
The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.
If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.
If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.
Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.
Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.
We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.
Scammers stole $1.27m from a Hong Kong man after tricking him with AI
The scheme impersonated his father using AI deepfake tech
Experts say using a secret codeword can thwart the fraudsters
A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used artificial intelligence (AI) on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate.
According to the Hong Kong police’s Cyberdefender platform (via the South China Morning Post), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000).
This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings.
Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.”
If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling two-factor authentication on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.
How to beat the fraudsters
(Image credit: Brett Jordan / Unsplash)
Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe.
As reported by the BBC, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.”
One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity.
When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.”
As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, cryptocurrency or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist.
Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.
Researchers tested AI-generated patches on six CVEs with poor success rates
Many fixes failed, altered behavior, or introduced new vulnerabilities
Guidance improved outcomes, leading to FLAWED evaluation harness release
When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.
Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.
As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.
FLAWED work?
This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well.
Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem.
The researchers created an acronym for automated LLM patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."
Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance.
This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes.
Attackers cloned AI skills, later adding malicious code to steal credentials
Zenity Labs found millions of installs and dozens of dangerous skill variants
Vercel and Microsoft removed malicious skills, but manual removal is still required
AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.
Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.
However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agents to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers.
Dozens of malicious skills
While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users).
And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks.
These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update.
Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.
Imagine attending a peaceful demonstration, only to have hidden cameras scan your face, match your identity, and log your details into a police database within seconds. This scenario is at the heart of a debate that reignited in Italy last week, highlighting a high-stakes clash between public safety and personal privacy.
From London and Paris to Amsterdam and Berlin, police forces across democratic Europe are increasingly piloting AI-powered face-scanning in public spaces and at political demonstrations.
While European leaders frame the technology as a necessary tool to combat crime, privacy advocates warn that facial recognition creates a chilling effect on the right to peaceful assembly and free expression. And the long-term risk may be even more troubling: once facial recognition is normalized, expanding its reach may be the next natural step.
How police in Europe use facial recognition at protests
Facial recognition technology (FRT) is a biometric tool that uses AI to identify individuals by analyzing their facial geometry — such as the distance between the eyes or the contour of the jawline — against a database. This software creates a unique digital signature, often called a "faceprint," which can be integrated directly into CCTV networks, drones, apps, and mobile police units.
Law enforcement deploys FRT in several ways, with Live Facial Recognition (LFR) being the most controversial. LFR scans real-time video feeds to cross-reference passersby against police watchlists almost instantaneously.
By contrast, retrospective facial recognition (RFR) functions more like traditional fingerprinting. Rather than scanning crowds live, police analyze recorded footage or photographs after an event to identify suspects.
This is the technology Italian lawmakers attempted to regulate last week, though police forces across the UK, France, the Netherlands and other European nations have already routinely deployed it.
At first glance, RFR might appear less intrusive — simply another investigative tool for law enforcement to access when necessary. However, human rights experts argue the distinction is misleading.
According to Chloé Berthélémy, Senior Policy Advisor at European digital rights network EDRi, the difference between live and post-event scanning is "largely a procedural distinction."
Speaking to TechRadar, Berthélémy warned: "In human rights terms, there is no salient difference between real-time and post-remote biometric identification. Threats posed to rights and freedoms are not reduced just because authorities or companies have extra time to review footage."
Berthélémy also cautions against the rise of Algorithmic Video Surveillance (AVS) — a system she labels "fundamentally unreliable." AVS uses AI software to analyze live video feeds and automatically flag suspicious or dangerous behavior.
Unlike facial recognition, AVS doesn't log facial features. Instead, it is trained to detect behavioral anomalies and physical triggers, such as sudden crowd surges, unattended luggage, weapons, fires, or individuals falling.
The 2024 Paris Olympic Games served as a testing ground for this technology, making France the first EU member state to legalize AI video analytics.
What European law says about facial recognition and our right to privacy
While facial recognition technology poses a risk to personal privacy, explicit statutory frameworks governing its use remain scarce.
Despite nearly a decade of police trials, the UK still lacks specific legislation governing facial recognition — a gap that Jasleen Chaggar, Senior Legal and Policy Officer at Big Brother Watch, warns has created a "real legal vacuum."
Chaggar explained to TechRadar that British police forces instead rely on a patchwork of common law precedents, existing data protection acts, and broader human rights legislation.
Although the UN Human Rights Committee called on the UK to end police facial recognition at protests, Chaggar notes that governments have resisted statutory regulation, citing police "operational independence."
"This has effectively given police a very long leash to experiment with these technologies," Chaggar told TechRadar. "And now we're in a tipping point situation where it's about to be expanded all over the country, and there's a real necessity for those legal frameworks to be in place."
❌We don't consent to biometric ID checksPolice will be using live facial recognition at @boardmasters festivalThis tech doesn’t just record what you do, your face becomes a barcode in the same way as your fingerprint or DNA#StopFacialRecognition⤵️https://t.co/9do8SIF81t pic.twitter.com/VSgXMTuX1YAugust 6, 2026
In contrast, the European Union's AI Act establishes a binding legislative framework across all member states. While offering greater legal clarity than the UK's approach, digital rights campaigners view the legislation as only a partial victory.
Dr. Matt Mahmoudi, campaign lead for Amnesty International's 'Ban the Scan' initiative, warns that failing to enact a total ban on public biometric surveillance creates broad national security exemptions that jeopardize fundamental rights.
"And it's not just the right to privacy. It's not just the right to protest and the freedom of assembly and expression. It's also the right to equality and non-discrimination," Mahmoudi told TechRadar.
The end of anonymous dissent?
Before facial recognition technology was deployed in public spaces, citizens attending demonstrations could rely on a degree of practical anonymity. Biometric surveillance fundamentally alters that expectation.
Digital rights experts interviewed by TechRadar agree that this level of intrusion steadily erodes civic space. The knowledge that your face is being scanned and cross-referenced against a police watchlist actively deters citizens from attending demonstrations.
“You may decide not to exercise your democratic rights because you're afraid of how it might be perceived by the authorities,” Big Brother Watch's Jasleen Chaggar explained.
Yet this chilling effect extends far beyond the physical cameras deployed at a single rally.
Facial recognition does not operate in isolation. It depends on extensive, often covert data harvesting. To construct watchlists, authorities aggregate imagery from diverse sources, including scraped social media profiles, government identity databases, police custody photos, CCTV archives, and commercial biometric databases.
(Image credit: HQuality / Shutterstock)
As Amnesty International’s Dr. Matt Mahmoudi explains, extensive data aggregation transforms ordinary digital footprints into a pervasive surveillance dragnet.
"Facial recognition is not a simple technology, but a system that effectively weaponizes your entire daily life," Mahmoudi told TechRadar.
Beyond baseline privacy concerns, the underlying technology remains prone to systemic errors.
Although computer vision algorithms have advanced in recent years, privacy campaigners emphasize that inherent system limitations remain. As Big Brother Watch's Jasleen Chaggar highlights, because facial recognition relies on probabilistic matching — calculating similarity scores rather than absolute matches — the technology can never be entirely error-free.
Beyond faces: the evolution of biometric surveillance
Even as lawmakers scramble to regulate facial recognition, law enforcement's appetite for public surveillance continues to expand.
In the UK, the growth is reinforced by stricter protest laws like the 2023 Public Order Act, with police monitoring group Netpol warning that enforcement will inevitably rely on an increased use of live facial recognition during demonstrations.
The obvious immediate danger is that eliminating anonymous dissent could permanently reshape democratic participation. However, privacy advocates warn of an even broader threat: biometric surveillance expanding beyond simple identification into behavioral classification.
Border control authorities are already experimenting with pairing facial recognition with emotion detection and gait analysis — the automated tracking of how an individual walks — which campaigners say could be used to target political demonstrations.
Amnesty International’s Dr. Matt Mahmoudi says that normalizing facial recognition paves the way for other speculative tools that could "fundamentally erode the presumption of innocence."
This rapid technological expansion forces a fundamental question upon democratic societies: how much liberty are citizens expected to trade for security? When scanning a crowd becomes routine policing, public squares risk morphing from spaces of free expression into arenas of perpetual surveillance — where a face is only the initial data point.
Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms
Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data
Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026
Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.
BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their credentials and authentication tokens.
Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid.
Stealing millions
Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones.
That is also a good way to spot who the potential victims are, and according to a new report from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc.
Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place.
The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too.
In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.
Split VPN has been accused of breaching its no-log policies
It allegedly leaked 58M connection logs, which SplitVPN denies as its own
Users trusting a no-log policy is not enough
Russian SplitVPN (formerly NotVPN) has been accused of breaching its own no-log policy after a data leak exposed a MySQL database containing a variety of data linked to the service, including a staggering 58 million alleged connection logs.
While the VPN provider — whose service is widely used to bypass blocks in countries with heavy censorship — told TechRadar that any allegations it keeps logs are false, the incident highlights the limitations of no-logs policy when things go wrong.
Even with the best VPNs, no-log policies are often based on trust rather than verifiable safeguards, meaning they may not give users a clear picture of the risks users could face if their VPN were exposed to a breach — particularly in countries where criminal prosecution due to the illegal use of VPNs is real.
A no-logs VPN policy means a VPN pledges not to collect or share users' information, including search queries, websites visited, time spent on them, and downloads, while they are connected to one of its servers.
However, it remains difficult for users to verify these claims for themselves. That is why the most secure VPNs have their policies regularly audited by independent organisations, ensuring their privacy promises are genuine and not just a fabricated image.
SplitVPN's alleged data breach
On July 21, a threat actor on the Altenen cybercrime forum distributed a 17 GB SQL database claimed to have been stolen from SplitVPN and which allegedly contained a staggering amount of connection logs alongside user records, devices and payments.
The research team at Mysterium VPN analysed the database and claimed part of it (known as 'deviceproxy') indeed contained around 58 million connection logs.
Although this consisted of anonymised metadata indicating which device had connected to which server and at what time rather than complete browsing histories, SplitVPN maintains that it does not retain such data in accordance with its no-logs policy.
(Image credit: MysteriumVPN)
SplitVPN told TechRadar that while the leaked subscription metadata — including email addresses, users' countries of origin, subscription status, masked credit card information and device names — is authentic, the deviceproxy table instead is entirely fabricated.
"The third-party listing claims 58 million connection logs, but this is a fabrication added to inflate the price," a company spokesperson said.
"Because we do not generate or store device-server-timestamp mappings, any records claiming to show this are not from our infrastructure," they added. "The exposed data contains only basic account information, which fully aligns with our no-logs commitment."
SplitVPN added that immediately after discovering the breach, they changed all VPN server node IPs, rotated all access credentials and encryption keys, closed the vulnerability, and engaged external security specialists to audit their infrastructure. Operations have now returned to normal.
The lesser of two evils
While it is arguably nearly impossible to independently verify the deviceproxy data’s authenticity, both scenarios present users with fundamental issues.
If allegations are true, the existence of these logs would directly contradict Split VPN's no-logs policy. When cross-referenced with the IP address of the most recent connection and hardware identifiers, these logs could be sufficient to determine who connected, from where, to which server, and when, putting millions of users in areas with heavy censorship at serious risk.
If claims are fabricated, users are still forced to rely on conflicting statements that they cannot independently verify, with leaked official data potentially causing concern amongst users living in countries where VPN usage is banned.
To ensure your privacy is respected, always look for a privacy policy audit and additional security features including kill switches, double VPN servers, and post-quantum encryption. Advanced technologies such as RAM-only servers or advanced cryptographic privacy can really make a difference. Ultimately, words pass, but technical expertise remains —especially when it’s your data that’s under threat.
Huntress saw Oracle SQLi used to deploy rare khunt toolkit
Khunt enabled OS commands, credential theft, and registry hive exfiltration
Defense includes input sanitation and more
Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely.
Security researchers Huntress, who were called in to investigate the incident, said the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.
This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.
How to defend
“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”
As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more.
Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained.
To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.”
Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.