Reading view

There are new articles available, click to refresh the page.

'It's Stalin's dream' — Quote of the day by software pioneer Richard Stallman on the tracking capabilities of cell phones

The programmer Richard Stallman is not a household name, but his work has been instrumental in building the software industry, as has his long-term campaign for free software. He's also been a huge advocate for privacy in the digital age, and has railed against the rise of cell phones for that reason.

Who needs phones anyway?

Stallman first disclosed his views on cell phones in an interview with Network World, during a time in which smartphones were exploding in popularity.

Quote of the day

This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. Read the full series here.

During this interview, Stallman indicated his long-held belief that the portable phones that many millions use would be the perfect tool that authoritarian forces could exploit and use to track the movements of populations.

He also advocated for free software, which you would expect from the founder of the Free Software Foundation (FSF), which he established in 1985. This was backed by the creation of the GNU project – a free software, mass collaboration movement to give users freedom of choice to use and develop software for their devices.

The legacy of free software

Despite his reluctance to ever use a cell phone, one of Stallman's achievements – which he himself acknowledged in the interview – was the third-party version of the Android mobile OS, from which all proprietary software was stripped out.

He pointed to new systems like Replicant, an alternative version of Android, that can run on certain devices without additional proprietary software. The catch is that this only works with older and outdated handsets, like the Samsung Galaxy S3 or the Galaxy Note 2.

Top US defense device maker IEH Corporation admits hackers broke into its systems

  • Attackers stole IEH employee credentials via a fake Microsoft login page
  • Inbox access exposed sensitive defense‑related communications and technical documentation
  • Malicious mailbox rules were removed as IEH contained the unauthorized access

Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.

In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”.

The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.

Malicious mailbox rules

“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.

The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.

IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated.

The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”

IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran.

IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.

Via The Record

US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people

  • Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems
  • Breach source and methods remain unknown, with no group claiming responsibility
  • Stolen data poses major fraud risks, prompting free identity monitoring from Kroll

US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.

The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.

The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.

Supply chain woes

The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data.

No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods.

ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.

Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in identity theft and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.

Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year.

According to BleepingComputer, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.

Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know

  • Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps
  • Flaws enabled account takeover, code execution, and traffic hijacking via bloatware
  • Samsung patched all reported issues, affecting hundreds of millions of devices

Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.

For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.

Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation.

Arbitrary code execution

The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on GitHub.

Most Android smartphone manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place.

This 'bloatware' is also one of the key selling propositions of Google Pixel devices, since these are considered “stock Android”, or bloatware-free.

Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:

“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”

Levi's reveals security tear may have let hackers steal important corporate data

  • Attackers used social engineering to access Levi’s network and steal corporate data
  • Details on stolen information, methods, and perpetrators remain largely undisclosed
  • Voice‑phishing extortion groups are suspected, though no one has claimed responsibility

Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.

The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.

After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.

Was it UNC6671?

In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted.

The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever.

While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, some publications have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there.

The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant remote access, or to visit a malicious credential-grabbing landing page.

From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data.

We have reached out to Levi’s with further questions and will update the article if we get an answer.

Via BleepingComputer

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks

  • Kimsuky used local AI tools to evade monitoring and enhance operations
  • Researchers observed extensive AI-driven capability building across the group’s infrastructure
  • Defenders urged behavior-based detection to spot evolving AI-enabled threats

North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.

When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and terminating multiple ChatGPT accounts used in phishing and human trafficking.

That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services.

"Consistent process of capability development"

The attacks were spotted by security researchers Genians who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.

Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.

Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat.

“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.

As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”

“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”

OpenAI says Daybreak will expand to offer specialized cyber services 

OpenAI announced Monday  it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.

In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program  – which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work – and introducing a new model variant.

Daybreak Blue, powered by OpenAI’s ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as “a recommended starting point for most defenders” that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation. 

Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around “dual-use cyber tasks.”

According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.

OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.

“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” the company said in a blog. “Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense.”

Additionally, OpenAI announced a partnership program with 16 major cybersecurity providers, saying organizations could access their models through their existing security services. The partners include IBM, CrowdStrike, Accenture, Ernst & Young, KPMG, Palo Alto Networks, Cisco, Cloudflare, Sophos and others. 

“These partners bring deep security expertise and established relationships with organizations around the world,” OpenAI said in its blog. “By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster.”

Companies like OpenAI, Anthropic and others are trying to rebalance their priorities after a string of AI-agent sandbox escapes have rattled policymakers and caused some cybersecurity experts to question if AI companies are doing enough to properly isolate the models from the internet during testing. Last week, OpenAI said it was intentionally slowing down development of its newer “Astra” model in order to develop better guardrails to restrain its behavior.

Cybersecurity and AI experts have told CyberScoop that while AI systems have greatly improved at finding and exploiting vulnerabilities in software code, they still require substantial human guidance and supporting infrastructure to operate as intended.

Additionally, some research has shown that without such guidance, even near-frontier models can struggle to fully patch a discovered vulnerability or avoid introducing new bugs with their fixes.

The post OpenAI says Daybreak will expand to offer specialized cyber services  appeared first on CyberScoop.

NATO and an AI startup can now name and track software vulnerabilities

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week

The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company with offices in San Francisco and Prague, joined as CVE numbering authorities under the ENISA Root. The CVE program assigns a unique record to each publicly disclosed security flaw so that governments, vendors and researchers have a common marker when referring to particular vulnerabilities. 

Twenty numbering authorities now sit under the ENISA Root, with 12 brought in by ENISA itself and eight moving over from the MITRE Root, run by the U.S. nonprofit that has handled the program’s daily work for more than 20 years.

Hans de Vries, ENISA’s chief cybersecurity and operations officer, linked the growth to changes in how people find flaws. 

“Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities,” he said in a statement. He said ENISA’s role helps build a “more globally representative, resilient, and scalable vulnerability identification ecosystem.”

The two new members show how bespoke each member is within its authority. The NATO Cyber Security Centre can now assign CVE IDs to eligible flaws across the NATO enterprise. The agency said that will make tracking more consistent and let the alliance share information with trusted partners sooner. The center guards NATO’s networks, watches for threats and coordinates the response when incidents hit.

Meanwhile, AISLE’s authorization is narrower. The company said in a July press release that the designation covers vulnerabilities discovered in its own products, allowing it to publish identifiers without waiting for a third-party authority to process a request. 

Jaya Baloo, the company’s co-founder, described the step as “foundational” and said coordinated disclosure “starts with holding your own products to the same standard you expect of everyone else.” Separately from the designation, the company said its researchers have disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache and OpenEMR, each coordinated through the relevant authority for that project.

The changes come as the CVE process continues to involve amid program upheaval and the torrent of vulnerabilities discovered by AI systems. 

The CVE program, run by CISA, narrowly escaped a sudden demise when a last-minute, 11-month contract extension averted a shutdown in April 2025. Since then, several competing databases from European nonprofits and other private entities have been stood up in order to better coordinate how vulnerabilities are tracked, disclosed, and ultimately patched.

Earlier this year, The Computer Incident Response Center Luxembourg (CIRCL) launched the Global CVE Allocation System, or GCVE, as an alternative to the CVE program.

The post NATO and an AI startup can now name and track software vulnerabilities appeared first on CyberScoop.

AI Assistant Hacks Gym Website In First Known Australian Autonomous Cyber Attack

An anonymous reader quotes a report from ABC News & Headlines: Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes. It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person -- it was artificial intelligence (AI). But Andrew was shocked by what happened next. His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software. Then it went further, kicking someone out of the waiting list who was ahead of Andrew -- something it was not asked to do. The accidental hack is the first known Australian case of an emerging risk from a new generation of AI capable of behaving in unexpected ways.

Read more of this story at Slashdot.

DEF CON hackers add new muscle to water utility protection

DEF CON hackers expanded their efforts to provide free cyber-defenses to rural water systems in the US to include managed detection and response providers, digital twins, and AI agents. On Friday, at the annual hacker’s conference, DEF CON Franklin and the National Rural Water Association (NRWA) announced a new program called the Water Watch Center. It will initially fund five providers - Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies - to help small water utilities serving fewer than 10,000 people detect and mitigate breaches. The security providers will exchange threat info and share that with the NRWA, which provides technical assistance and operational support to small water and wastewater utilities across all 50 states. “We've had our volunteer experts out for two years in these water utilities, in the trenches with these folks, and the thing that we've realized is that there's just not a scalable delivery mechanism for cyber for these utilities when there’s 150,000 of them, and 98 percent of them are small businesses,” Jake Braun told The Register during an interview at DEF CON. Braun co-founded the Franklin project at DEF CON in 2024, and 350 people signed up that year to donate their time and talent to securing water facilities. “We groped around in the dark for what to do, and eventually realized we already know how to do security for small businesses - it’s MSSPs,” Braun said. “So why don’t we just do that?” He described the new Water Watch Center as a pyramid, with the NRWA at the top, the managed detection and response providers’ sensors hunting for security vulnerabilities across the utilities’ networks, and then Franklin volunteers fixing issues or responding to instructions as needed. “We have five initial MSSPs, which will expand to 10 eventually, based on the 10 CISA regions,” Braun said. “And then below that, we have volunteers who can help, and connect water utilities to MSSPs, so we’re not just sending alerts. We can take the alerts that CISA and the ISAC put out, and deliver cybersecurity. That’s been the missing piece: there has been no delivery mechanism for cybersecurity that’s scalable nationally - that's what this is.” Suspected Iranian hackers have hit numerous water systems in recent weeks, and most were small, community systems that left programmable logic controllers directly exposed to the internet using default or weak passwords. There’s no indication that the attackers used AI to help plan or carry out these digital disruptions. However, as both cyber and national security experts told The Register during conversations on the sidelines of Black Hat and DEF CON, it’s only a matter of time until that happens. DEF CON Franklin has a plan for that scenario, too. The Water Watch Center also partnered with Vanderbilt University to apply research from the DARPA Cyber Agents for Security Testing and Learning Environment (CASTLE) program. This partnership will create digital twins for a few WWC water and wastewater system environments, and then researchers will deploy both red- and blue-team agents across these digital dupes. The red-team attack agents try to hack the water systems, testing the blue-team defenders’ automated detection and response capabilities, with the eventual goal of deploying AI-based defense to water and wastewater facilities across the US. “They let it fight each other a gazillion times, and then they figure out when does the blue team win, so we can train agents to then later drop into these 150,000 water utilities,” Braun said. “There's already a 500,000-person shortage of cyber professionals. The idea that we're magically going to find 150,000 new people is a fantasy. There is no other way to really be able to combat the AI attacks that are going to be coming at these things.” ®

❌