❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

MS-DEFCON 2: Is Search going to get better?

6 August 2026 at 03:45
ISSUE 23.31.1 β€’ 2026-08-06 By Susan Bradley The upcoming August updates include several promised fixes for Windows Search. The August updates will include several fixes, a few of which specifically target Search. I anticipate that the August updates will also bring a bumper crop of other vulnerabilities being patched, so I’m raising the MS-DEFCON level […]

Tracking the attacker

27 July 2026 at 03:22
ON SECURITY Tracking the attacker By Susan Bradley Recently, Apple, Adobe, Microsoft, and others released updates illustrating how much we are being impacted by AI. The three major vendors either sped up releases or released updates with a massive number of vulnerabilities. But does that make us more unsecure? Before I discuss some side effects […]

The patch apocalypse is here

20 July 2026 at 03:45
ISSUE 23.29 β€’ 2026-07-20 PATCH WATCH By Susan Bradley Well, the benefits of AI are clearly here β€” at least in terms of bug counts. Microsoft fixed 621 vulnerabilities this time around. However, take a breath β€” a big breath. Even with all those fixes that encompass both Windows and .NET, the updates are pushed […]

Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed

15 July 2026 at 14:29

Democratic senators pressed President Donald Trump’s pick for director of national intelligence on questions of election security and integrity Wednesday, but they didn’t leave his nomination hearing satisfied with the answers.

As is typical for Trump administration nominees, Jay Clayton wouldn’t answer definitively at his Senate Intelligence Committee confirmation hearing whether Joe Biden won the 2020 presidential election, saying only that he was β€œcertified,” while maintaining that he wasn’t an β€œelection denier.”

He said that the Office of the Director of National Intelligence’s responsibilities were β€œprincipally” outside the United States. But he claimed varying degrees of ignorance about his predecessor, Tulsi Gabbard, being physically present at an FBI raid of a Georgia election office in January, and wouldn’t comment on its appropriateness.

Democratic senators were also frustrated while trying to pin down Clayton, the U.S. attorney for the Southern District of New York who served as head of the Securities and Exchange Commission in Trump’s first term, on remarks about mail-in ballots and the California primary election results last month.

Multiple senators, including Mark Warner, D-Va., Angus King, I-Maine and Mark Kelly, D-Ariz., tried to get Clayton to say whether Biden won the 2020 election. The final exchange came with Jon Ossoff, D-Ga.

Clayton protested that he had already answered. β€œI think I’ve answered the question,” he said. β€œWe can keep doing this.”

Ossoff didn’t agree, telling him, β€œWell we’re going to keep doing it because you’re not being honest or forthright with the committee.”

β€œIsn’t it humiliating to be unable to answer this question?” he asked. β€œTo have to indulge the president’s delusions? We know, you know, everybody in this room knows the truthful answer to that question. Why can you not give it?”

Earlier Clayton had said, β€œI’m not an election denier,” but repeatedly wouldn’t answer β€œyes” or β€œno” on whether Biden won in 2020.

That matters because of the DNI’s role, Kelly said, and it was worrying that Clayton was seeking to avoid upsetting Trump, who has maintained despite all evidence that he lost the 2020 election.

β€œIt’s not about softening the edges when the truth is unpleasant,” Kelly said. β€œIt’s about delivering information.”

Clayton discussed the DNI’s role on election security at greater length in pre-hearing written answers.

β€œI understand that the DNI, as head of the Intelligence Community, has substantial statutory authority to address national intelligence threats to U.S. elections,” he said. β€œIn particular, the Director is responsible for the integration of national intelligence, which may include foreign intelligence threats to U.S. election activity. I also understand that Intelligence Community elements are authorized to cooperate with and provide appropriate intelligence and technical support to law enforcement agencies and that as head of the Intelligence Community, the DNI has oversight of those activities.”

A CNBC interview last month inspired some of the Democrats’ questions. Clayton said in response to questions about the California primaries that β€œOn the integrity side, we’re doing an absolutely terrible job. And the American people are right to question it.” 

He said mail-in ballots present an β€œopportunity for fraud,” despite studies showing exceptionally low rates of fraud using that method, and said β€œmail-in ballots being used by one group and not another… honestly and dishonestly” was a β€œquestion that everyone is now asking.”

Sen. Ron Wyden, D-Ore., asked him about what group Clayton was referring to.

β€œβ€I would like to see where you’re pulling those quotes from. I’ve been very careful about my remarks on this,” Clayton answered. β€œI’d like to see the whole passage.”

In his questionnaire, when asked if β€œit would be inappropriate for a DNI to comment publicly about unsubstantiated claims regarding mail-in-ballots and election fraud,” Clayton answered that β€œIf confirmed as DNI, any representations I make to the public, including about elections, will be informed by timely, objective national intelligence.”

Ossoff also had a tense exchange with Clayton when asking him about Gabbard’s appearance at the Fulton County office raid. Gabbard has said she was there because Trump asked her to be, in what subsequently became a highly publicized appearance because of questions about what the DNI would be doing at a law enforcement raid.

β€œI was made aware of it by you yesterday,” Clayton said.

Ossoff responded skeptically: β€œThe first time you learned that Director Gabbard was present at that raid was in my office yesterday?”

Said Clayton: β€œIt was the first time that in my recollection I’ve thought about it recently.”

β€œWhat?” Ossoff replied.

Warner, the top Democrat on the committee, told Clayton β€œI trust you” but it β€œstrains credulity” that he wasn’t aware of Gabbard being at the raid.

β€œTo be clear, the ODNI’s role is principally outside of the United States,” Clayton said.

On other topics, in his opening remarks, Clayton touted his SEC work on cybersecurity. In his questionnaire he said he would work to facilitate cyberthreat information sharing from his office.

He told Sen. Kirsten Gillibrand, D-N.Y., that he would evaluate whether the DNI should devote more resources to cybersecurity with federal government cyber experts being pushed out since Trump came back to office. Many Republicans are pushing to further reduce the size of Clayton’s office, contending it has become bloated beyond Congress’ original intentions as a coordinating body.

He said he supported renewal of Section 702 of the Foreign Intelligence Surveillance Act, which gives the executive branch controversial spying powers that Congress recently allowed to expire.

Trump has threatened to block renewal unless lawmakers advance his priority election bill. He said he will study how to β€œminimize the detrimental impact to our national security caused by the lapse in 702 authorities.” Some Democrats, meanwhile, have resisted action on the law until Trump’s pick for acting DNI Bill Pulte is gone, citing his prior efforts to investigate officials as head of the Federal Housing Finance Agency and lack of intelligence experience.

Because the GOP controls the Senate, Clayton is likely to get confirmed as DNI as long as no Republicans emerge in opposition. Wednesday’s hearing revealed no significant Republican objections.

Intelligence Chairman Tom Cotton, R-Ark., touted Clayton’s experience prosecuting terrorism cases and more.

β€œJay Clayton has worked hand in glove with our intelligence agencies and counterterrorism personnel to lock up criminals who threaten our national security,” Clayton said. β€œI encourage my colleagues to join me and get Mr. Clayton’s nomination over the finish line.”

The post Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed appeared first on CyberScoop.

Windows K2: Microsoft’s reported plan to fix Windows 11

13 July 2026 at 03:44
WINDOWS 11 By Martin Brinkmann To fix a bloated Windows 11, Microsoft has reportedly launched β€œProject K2” β€” a massive internal repair campaign For years, Windows fans have watched Microsoft stuff the operating system with features barely anyone asked for, all while core features such as File Explorer, Windows Search, and the general reliability of […]

MS-DEFCON 2: More patches from Apple and Adobe

9 July 2026 at 03:45
ISSUE 23.27.1 β€’ 2026-07-09 By Susan Bradley As a result of researchers’ using AI to do more in-depth code reviews of operating systems and applications, expect to see more security updates and more vulnerability counts. As Apple indicated to Reuters, the recent release of Apple security updates was done in an accelerated fashion because β€œβ€¦ […]

Felons, Fraudsters Flog Offensive Cybersecurity Startup

8 July 2026 at 08:31

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.

β€œOur business model is this,” reads a pinned post on top of the IRIS C2 account on X. β€œAttract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.”

The website linked in that profile β€” irisc2[.]com β€” says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring β€œzero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.”

The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC. The β€œcontact” link on the website for Calvexa Group β€” calvexagroup[.]com β€” forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts.

A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia.

Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller, and Pete Buttigieg, then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris.

In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected.

In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement.

In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.

Jacob β€œJay” Wohl’s GitHub account.

By the age of 17, Wohl had started multiple investment firms, and cultivated the nickname β€œWohl of Wall Street” after appearing on Fox News in 2015 to discuss his new hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, and ordered him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and was sentenced to two years of probation.

The market for previously unknown security vulnerabilities has always been populated by a colorful mix of researchers, academics, charlatans, clout-chasers and people actively involved in cybercrime communities. But the market for selling offensive security services to the U.S. government tends to be far more circumspect. Plenty of government contractors recruit vulnerability researchers and pay for the exclusive rights to novel software exploits, yet none of them do so quite as brazenly and openly as IRIS C2.

Recent posts from the Twitter/X account IRISC2 (@c2iris).

Indeed, KrebsOnSecurity was unaware of IRIS C2 until last month, when an attendee at a regional cybersecurity conference shared that Wohl and Calvexa Group were pestering people at the conference about selling their vulnerability research.

In an interview with KrebsOnSecurity, Wohl said Mr. Burkman was not involved in the day-to-day operations of IRIS C2. Wohl shared that IRIS C2 originally began as a penetration testing company, but shifted its focus recently to selling phone-hacking services to the government. Several times throughout the interview, Mr. Wohl mentioned working on federal government contracts, but when pressed for specifics said he was not at liberty to speak publicly about them.

Mr. Wohl said he does not have any formal education or training in computer science or information security, and that most of his knowledge on the matter is self-taught.

β€œI know more about tech than anyone,” Wohl bragged. β€œMy background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”

Wohl said security researchers bring the company unique vulnerability findings β€œon a regular basis,” but that in many cases those findings are preliminary and not fully fleshed-out.

β€œLet’s say someone finds a flaw in a media decoder on a phone,” Wohl said. β€œA lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do.”

Wohl claims IRIS C2 has approximately 40 employees, although he said none of them are allowed to list their employment on LinkedIn for operational security reasons. In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living. But if IRIS C2 has any other employees, they may be similarly unaware of Mr. Wohl’s history of outright fabrications β€” or even his real name.

In September 2024, Politico reported that Burkman and Wohl were bragging about big companies supposedly buying services from their now-defunct company LobbyMatic, which claimed to use artificial intelligence to assist in political lobbying efforts. However, Politico found the pair were running the company using pseudonyms, with Wohl reportedly adopting the name β€œJay Klein” and Burkman using the moniker β€œBill Sanders.” Politico reported that two of the former LobbyMatic employees resigned after learning of their true identities, while other employees only learned after they had left the company.

Update, July 9, 9:44 a.m. ET: Several readers pointed our attention to a March 31 publication from journalist Molly White, which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a β€œpresidential pardon to avert a miscarriage of justice” on behalf of the accused hacker, who has not yet been convicted.

June 29, 2026 Apple Updates

By: PKCano
30 June 2026 at 04:00
On June 29, 2026, Apple released Updates for MacOS Tahoe 26.5.2 and iOS/iPadOS 26.5.2. Apple is expected to release the next version of their Operating Systems, v26.6, in early July. Normally they package the Security Updates along with the new versions. But,Β  as reported by Reuters, Apple is releasing the updates early for macOS/iOS/iPadOS in […]

What to do with older tech

29 June 2026 at 03:42
ON SECURITY By Susan Bradley When I started writing this column, I planned to open with the forthcoming end of the Windows 10 ESU. Oops. On June 24, Microsoft changed its mind. It decided to extend the Windows 10 Extended Security Updates (ESU) program for another year, until October 12, 2027. You can find the […]

Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks

By: BHIS
24 June 2026 at 10:00

Insufficient egress filtering is a commonly identified vulnerability found during BHIS penetration tests. The insufficient egress filtering finding indicates that network traffic leaving the organization’s environment is not properly restricted.

The post Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks appeared first on Black Hills Information Security, Inc..

Controversial FISA spying law expired this week. The spying will continue.

By: Dissent
14 June 2026 at 08:12
On June 12, Jon Brodkin reported: Title VII of the Foreign Intelligence Surveillance Act (FISA) is set to expire at midnight tonight after Congress failed to pass an extension of the controversial spying law. But that doesn’t mean the government’s spying powers will disappear. Surveillance under Section 702 of FISA β€œoperates under yearlong certifications approved...

MS-DEFCON 2: Fixes for Windows 11

4 June 2026 at 03:45
ISSUE 23.22.1 β€’ 2026-06-04 By Susan Bradley Microsoft is starting to roll out its much-promised, dribbled fixes. Included in the upcoming June updates β€” and already included in the preview updates released on May 26, 2026 β€” KB5089573 includes the Secure Boot fixes and the beginning of many changes about which you’ve complained. Nonetheless, it’s […]

European authorities crack down on illegal streaming networks

3 June 2026 at 18:15

Authorities in Europe arrested 29 alleged cybercriminals and took down more than 27,000 illegal streaming URLs that pirated major sporting events, films and TV programming, Europol said Wednesday.

The continent-wide collaboration, led by Bulgaria and the European Union’s police agency, allowed authorities to dismantle nine organized crime groups supporting the illicit streaming networks, officials said. β€œOperation Kratos 2” focused on disrupting the networks’ underlying infrastructure and stretched for seven months before coming to a close in April.Β 

Officials did not name the suspects, groups or services targeted during the crackdown, but noted that investigators identified key players responsible for managing and operating the piracy platforms.

Europol said the streaming sites infringed on nearly 850,000 media across 169 domains.Β 

β€œWhat appears to consumers as cheap access to premium content is powered by complex criminal enterprises,” the agency said in a news release. Illegal streaming site operators host separate servers for customer-facing websites and illegal content, and distribute their services across multiple countries.

During the course of the operation, officials conducted 148 house searches, identified 86 suspects and referred 59 cases to courts for criminal proceedings.Β 

Investigators also worked with private-sector partners to identify nearly 4,400 new domains and more than 18,000 IP addresses linked to piracy and other illegal activity. Those efforts allowed authorities to report almost 400,000 additional URLs for suspension or removal.Β 

Live sports piracy networks are widespread and consistently tracked by antipiracy coalitions and authorities globally. Authorities in Egypt last year shut down Streameast, the most popular and largest illegal live sports streaming network at the time, with an operation that spanned 80 domains and logged more than 1.6 billion visits during the year prior.

Operation Kratos 2 was supported by anti-piracy associations, UEFA Europa League, La Liga, beIN Media Group and officials from Belgium, Bulgaria, Croatia, France, Greece, Ireland, Italy, the Netherlands, Poland, Romania, Spain, the United Kingdom and the United States.

The post European authorities crack down on illegal streaming networks appeared first on CyberScoop.

Snapdragon X2 is fast, but Windows on Arm holds it back

25 May 2026 at 03:44
SILICON By Matthew S. Smith Qualcomm’s Snapdragon X2 chips are mighty, but Windows on Arm can still be a mighty pain in the neck. In May 2024, I took the train up to Seattle for Microsoft’s Build developer conference. It’s usually a series of nerdy talks from passionate developers that end up overshadowed by hyper-corporate […]

MS-DEFCON 2: Sometimes there’s no fix

7 May 2026 at 03:45
ISSUE 23.18.1 β€’ 2026-05-07 By Susan Bradley It’s time to prepare for the May updates, which includes pausing and deferring them. That’s why the MS-DEFCON level is going to 2. There may be some confusion about the recent changes to the level. You’ll recall that I changed the level to 4 on April 28 and […]

Congress kicks the can down the road on surveillance law (again)

30 April 2026 at 16:53

Congress extended a controversial surveillance law for 45 days on Thursday, hours before its latest expiration following an earlier extension.

The Senate passed β€” then the House cleared β€” a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act, which authorizes warrantless surveillance of foreign targets. But those targets are sometimes communicating electronically with Americans, and intelligence officials can search the database using their identifying information, which has long given privacy groups and privacy-minded lawmakers heartburn.

The 45-day reprieve gives lawmakers more time to hammer out a lasting deal, and comes after the leaders of the Senate Intelligence Committee agreed to send a letter to the Director of National Intelligence and attorney general, seeking swift declassification of a letter on a classified ruling from the Foreign Intelligence Surveillance Court.

Sen. Ron Wyden, D-Ore., had sought release of that opinion, and had resisted giving unanimous consent for the latest short-term extension to move forward until Senate Intelligence Chairman Tom Cotton, R-Ark., and top panel Democrat Mark Warner of Virginia agreed to send the letter.

A declassification review was already underway, but the Cotton-Warner letter states that β€œWe expect that this declassification review will be completed and the FISC opinion released publicly within 15 days,” according to Wyden, speaking on the Senate floor.

The March 17 opinion reportedly came with annual recertification of the warrantless surveillance program. The Justice Department is appealing that ruling because it blocked them from using certain tools to analyze communications.

β€œA few weeks ago, the Foreign Intelligence Surveillance Court found major compliance problems related to the surveillance law known as section 702,” Wyden said earlier this month. β€œThese compliance problems are directly related to Americans’ Constitutional rights.”

Senate Majority Leader John Thune, R-S.D., said the extension will give lawmakers additional room to hold β€œdiscussion on reforms.”

The House this week had passed a 3-year reauthorization with some changes to the surveillance program, but key to doing so was leadership’s agreement to attach legislative language on a separate matter that would ban a central bank digital currency. Thune had said that language was going nowhere in the Senate.

On Thursday, the House voted 261-111 to extend the law for 45 days. President Donald Trump has sought a β€œclean” 18-month reauthorization of the surveillance powers.

The extension continues a perennial ritual for the Hill when it comes to Section 702: A deadline looms, and Congress kicks the can down the road repeatedly.

The post Congress kicks the can down the road on surveillance law (again) appeared first on CyberScoop.

April 22, 2026 Apple Updates

By: PKCano
23 April 2026 at 04:00
Apple released Updates forΒ iOS 26.4.2/iPadOS 26.4. and iOS 18.7.8/iPadOS 18.7.8 on April 22, 2026.Β  The updates address CVE-2026-28950, a bug in the Notification Services. Updates that Apple released today address a security vulnerability that the FBI recently used to extract Signal message previews from an iPhone even after the app was deleted. Apple claims the […]
❌
❌