<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/14/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>NSA Issues Microsoft Exchange Server &#x2018;High-Risk Of Compromise&#x2019; Alert</title><link>https://nsaneforums.com/news/security-privacy-news/nsa-issues-microsoft-exchange-server-%E2%80%98high-risk-of-compromise%E2%80%99-alert-r32232/</link><description><![CDATA[<p>
	Microsoft has been in the media spotlight recently as Windows attackers exploit a no-patch vulnerability, emergency security updates are issued for another ongoing exploit, and the Cybersecurity and Infrastructure Security Agency tells federal agencies to update now as Windows Server attacks confirmed in the wild. It’s not all bad news, though: the National Security Agency has issued a security best practices guide to defending your Microsoft Exchange Servers, with CISA warning the platform remains “at high risk of compromise.”
</p>

<p>
	 
</p>

<p>
	<span style="font-size:20px;"><strong>Microsoft Exchange Server Security Best Practices</strong></span>
</p>

<p>
	 
</p>

<p>
	This isn’t the first time that U.S. security agencies have warned about the dangers of attacks targeting Microsoft Exchange Servers, and likely will not be the last. It is, however, a long-overdue acceptance of the need for official guidance when it comes to Microsoft Exchange Server security best practices. Not just for government agencies, but all enterprises. Sure, there’s plenty of such advice already out there, not least from Microsoft itself, but the added weight of CISA and the NSA certainly isn’t to be sniffed at.
</p>

<p>
	 
</p>

<p>
	Thankfully, for such things, the document itself is relatively short and to the point at just 10 pages of Microsoft Exchange Server security guidance. The brevity is noted by the NSA and CISA within the introductory paragraph: “This document outlines several security best practices, but is not an all-inclusive hardening guide. Active monitoring for compromises and planning for potential incidents and recovery, while not discussed in this guidance, are equally important areas for Exchange.”
</p>

<p>
	 
</p>

<p>
	So, what does the guidance cover then?
</p>

<p>
	 
</p>

<p>
	While you are, rather obviously, recommended to go and read the entire best practices guidance yourself, here’s the bullet point summary:
</p>

<p>
	 
</p>

<ul>
	<li>
		    Maintain security updates and patching cadence
	</li>
	<li>
		    Migrate end-of-life Exchange Servers
	</li>
	<li>
		    Ensure Emergency Mitigation Service remains enabled
	</li>
	<li>
		    Apply security baselines
	</li>
	<li>
		    Enable built-in protections
	</li>
	<li>
		    Restrict administrative access
	</li>
	<li>
		    Harden authentication and encryption
	</li>
	<li>
		    Configure Transport Layer Security
	</li>
	<li>
		    Configure Extended Protection
	</li>
	<li>
		    Configure Kerberos and SMB instead of NTLM
	</li>
	<li>
		    Configure Modern Authentication and multifactor authentication
	</li>
	<li>
		    Configure certificate-based signing of PowerShell serialization
	</li>
	<li>
		    Configure Strict Transport Security
	</li>
	<li>
		    Configure Download Domains
	</li>
	<li>
		    Use role management and split permissions
	</li>
	<li>
		    Use P2 FROM header manipulation detection
	</li>
</ul>

<p>
	 
</p>

<p>
	Look, nobody said that security was easy, OK? But as the NSA concluded, “securing Exchange servers is essential for maintaining the integrity and confidentiality of enterprise communications and functions.” By using the best practices outlined above, you can help reduce the risk to your organization from Microsoft Exchange Server attackers.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.forbes.com/sites/daveywinder/2025/11/02/nsa-issues-microsoft-exchange-server-high-risk-of-compromise-alert/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32232</guid><pubDate>Sun, 02 Nov 2025 13:54:28 +0000</pubDate></item><item><title>Beware of fake Microsoft Teams ads spreading ransomware</title><link>https://nsaneforums.com/news/security-privacy-news/beware-of-fake-microsoft-teams-ads-spreading-ransomware-r32219/</link><description><![CDATA[<p>
	<span style="font-size:16px;">Ransomware gang uses fake Microsoft Teams ads to deliver malware </span>
</p>

<p>
	 
</p>

<p>
	<strong>What Happened:</strong> Heads up, everyone. There’s a really nasty new scam making the rounds, and it’s targeting anyone searching for Microsoft Teams.
</p>

<p>
	 
</p>

<ul>
	<li>
		A ransomware gang called Rhysida has been buying up ad space on search engines, especially Bing. So, when you search for “Microsoft Teams,” their fake ad might be the first thing you see. It looks totally legit, like it’s pointing right to the real Microsoft download page.
	</li>
	<li>
		But it’s a trap. When you click it, it sends you to a bogus website (one that’s probably spelled almost like the real one, a tactic called “typosquatting”).
	</li>
	<li>
		You download what you think is the Teams installer, but it’s actually a piece of malware called OysterLoader. Once that’s on your system, it can let the hackers in to eventually lock up all your files with ransomware.
	</li>
</ul>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="cybersecurity-hacks-coronavirus.jpg?resi" class="ipsImage" data-ratio="75.10" height="469" width="720" src="https://www.digitaltrends.com/wp-content/uploads/2020/04/cybersecurity-hacks-coronavirus.jpg?resize=1536,1002" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">EThamPhoto / Getty Images / EThamPhoto / Getty Images</span>
</p>

<p>
	 
</p>

<p>
	<strong>Why This Is Important:</strong> This is a scarily smart campaign. These guys, who have been linked to over 200 data leaks, are part of a “ransomware-as-a-service” network (yep, that’s a real thing).
</p>

<p>
	 
</p>

<ul>
	<li>
		To make the scam work, they’re using a bunch of digital certificates – those little things that are supposed to tell Windows, “Hey, this software is legit and safe.”
	</li>
	<li>
		Because the malware has a (likely stolen) certificate, your computer trusts it, and your antivirus program might not even flag it. One security firm said that at first, almost no antivirus tools were catching this thing, giving the hackers plenty of time to get in.
	</li>
	<li>
		Microsoft is in a high-stakes game of whack-a-mole; they’ve already revoked over 200 of these fake certificates, but the bad guys just keep evolving.
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Why Should I Care:</strong> This isn’t just a problem for big companies. They are hitting individuals, schools, and small businesses – anyone who might be looking for popular software.
</p>

<p>
	 
</p>

<ul>
	<li>
		If you’ve downloaded Microsoft Teams (or any popular app, really) from a search ad recently, you could be at risk.
	</li>
	<li>
		Clicking that one wrong link could be all it takes to get your entire computer – all your photos, documents, and personal files – encrypted and held for ransom.
	</li>
</ul>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="cybersecurity-lede-photo.jpg" class="ipsImage" data-ratio="75.10" height="480" width="720" src="https://www.digitaltrends.com/wp-content/uploads/2019/10/cybersecurity-lede-photo.jpg" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">TheDigitalWay/Pixabay / Pixabay</span>
</p>

<p>
	 
</p>

<p>
	<strong>What’s Next:</strong> Security experts are all over this, and Microsoft is fighting back, but these groups adapt fast. The best defense for you? It’s pretty simple:
</p>

<p>
	 
</p>

<ul>
	<li>
		Never, ever download software from a search ad.
	</li>
	<li>
		Seriously, just don’t. Always go directly to the official website yourself (like typing in microsoft.com by hand).
	</li>
	<li>
		Using an ad blocker on your browser is also a fantastic idea, as it will probably stop you from even seeing these malicious ads in the first place. Stay safe out there.
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong><a href="https://www.digitaltrends.com/computing/beware-of-fake-microsoft-teams-ads-spreading-ransomware/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32219</guid><pubDate>Sat, 01 Nov 2025 23:42:42 +0000</pubDate></item><item><title>New Warning As Microsoft Windows Attacks Confirmed &#x2014; No Fix Available</title><link>https://nsaneforums.com/news/security-privacy-news/new-warning-as-microsoft-windows-attacks-confirmed-%E2%80%94-no-fix-available-r32206/</link><description><![CDATA[<p>
	No sooner has Microsoft issued an emergency security update for Windows users following attacks spotted in the wild, so news breaks of another ongoing cyberattack targeting Windows. This one, however, does not have a fix as of yet. Here’s what you need to know about CVE-2025-9491. 
</p>

<p>
	 
</p>

<p>
	<span style="font-size:18px;"><strong>CVE-2025-9491 Is Now Being Exploited by Attackers in the Wild — No Fix Available from Microsoft</strong></span>
</p>

<p>
	 
</p>

<p>
	Just as you might have thought that things were improving on the security front as far as Windows users were concerned, with new admin protections announced, and another year of free security updates for Windows 10, comes the latest hammer blow: an active and widespread cyber espionage campaign exploiting what is now a critical vulnerability, with no Microsoft security patch to fix it.
</p>

<p>
	 
</p>

<p>
	A detailed and highly technical analysis from the cybersecurity boffins at Arctic Wolf Labs has confirmed that threat actors affiliated with China are currently exploiting a Windows remote code execution vulnerability, CVE-2025-9491, first reported in March, yes, March, in ongoing attacks.
</p>

<p>
	 
</p>

<p>
	The attacks appear to be targeting “European diplomatic entities in Hungary, Belgium, and additional European nations,” the analysis determined, but now that the exploit cat is out of the bag, it would not be at all surprising were this vulnerability to be used in much broader campaigns until Microsoft can fix it. So do not think that it does not concern you; it most certainly could.
</p>

<p>
	 
</p>

<p>
	The current attacks use a chain of phishing emails with an embedded URL that ultimately leads to malicious LNK files, or Windows shortcuts, being delivered to the target. By exploiting the vulnerability that allows obfuscated PowerShell commands to be executed and “extract and deploy a multi-stage malware chain,” Arctic Wolf said, “culminating in PlugX remote access trojan deployment,” the cyber damage is then done.
</p>

<p>
	 
</p>

<p>
	I have approached Microsoft for a statement and will update this article as soon as I hear back, but in the meantime, with no readily available security patch to apply, Windows users are advised to block .lnk files from any untrusted source within their Windows Explorer settings.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.forbes.com/sites/daveywinder/2025/11/01/new-warning-as-microsoft-windows-attacks-confirmed---no-fix-available/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32206</guid><pubDate>Sat, 01 Nov 2025 12:15:00 +0000</pubDate></item><item><title>OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically</title><link>https://nsaneforums.com/news/security-privacy-news/openai-unveils-aardvark-gpt-5-agent-that-finds-and-fixes-code-flaws-automatically-r32201/</link><description><![CDATA[<p>
	OpenAI has announced the launch of an "agentic security researcher" that's powered by its GPT-5 large language model (LLM) and is programmed to emulate a human expert capable of scanning, understanding, and patching code.
</p>

<p>
	 
</p>

<p>
	Called Aardvark, the artificial intelligence (AI) company said the autonomous agent is designed to help developers and security teams flag and fix security vulnerabilities at scale. It's currently available in private beta.
</p>

<p>
	 
</p>

<p>
	"Aardvark continuously analyzes source code repositories to identify vulnerabilities, assess exploitability, prioritize severity, and propose targeted patches," OpenAI noted.
</p>

<p>
	 
</p>

<p>
	It works by embedding itself into the software development pipeline, monitoring commits and changes to codebases, detecting security issues and how they might be exploited, and proposing fixes to address them using LLM-based reasoning and tool-use.
</p>

<p>
	 
</p>

<p>
	Powering the agent is GPT‑5, which OpenAI introduced in August 2025. The company describes it as a "smart, efficient model" that features deeper reasoning capabilities, courtesy of GPT‑5 thinking, and a "real‑time router" to decide the right model to use based on conversation type, complexity, and user intent.
</p>

<p>
	 
</p>

<p>
	Aardvark, OpenAI added, analyses a project's codebase to produce a threat model that it thinks best represents its security objectives and design. With this contextual foundation, the agent then scans its history to identify existing issues, as well as detect new ones by scrutinizing incoming changes to the repository.
</p>

<p>
	 
</p>

<p>
	Once a potential security defect is found, it attempts to trigger it in an isolated, sandboxed environment to confirm its exploitability and leverages OpenAI Codex, its coding agent, to produce a patch that can be reviewed by a human analyst.
</p>

<p>
	 
</p>

<p>
	OpenAI said it's been running the agent across OpenAI's internal codebases and some of its external alpha partners, and that it has helped identify at least 10 CVEs in open-source projects.
</p>

<p>
	 
</p>

<p>
	The AI upstart is far from the only company to trial AI agents to tackle automated vulnerability discovery and patching. Earlier this month, Google announced CodeMender that it said detects, patches, and rewrites vulnerable code to prevent future exploits.
</p>

<p>
	 
</p>

<p>
	The tech giant also noted that it intends to work with maintainers of critical open-source projects to integrate CodeMender-generated patches to help keep projects secure.
</p>

<p>
	 
</p>

<p>
	Viewed in that light, Aardvark, CodeMender, and XBOW are being positioned as tools for continuous code analysis, exploit validation, and patch generation. It also comes close on the heels of OpenAI's release of the gpt-oss-safeguard models that are fine-tuned for safety classification tasks.
</p>

<p>
	 
</p>

<p>
	"Aardvark represents a new defender-first model: an agentic security researcher that partners with teams by delivering continuous protection as code evolves," OpenAI said. "By catching vulnerabilities early, validating real-world exploitability, and offering clear fixes, Aardvark can strengthen security without slowing innovation. We believe in expanding access to security expertise."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2025/10/openai-unveils-aardvark-gpt-5-agent.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32201</guid><pubDate>Sat, 01 Nov 2025 10:25:06 +0000</pubDate></item><item><title>Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack</title><link>https://nsaneforums.com/news/security-privacy-news/nation-state-hackers-deploy-new-airstalk-malware-in-suspected-supply-chain-attack-r32200/</link><description><![CDATA[<p>
	A suspected nation-state threat actor has been linked to the distribution of a new malware called Airstalk as part of a likely supply chain attack.
</p>

<p>
	 
</p>

<p>
	Palo Alto Networks Unit 42 said it's tracking the cluster under the moniker CL-STA-1009, where "CL" stands for cluster and "STA" refers to state-backed motivation.
</p>

<p>
	 
</p>

<p>
	"Airstalk misuses the AirWatch API for mobile device management (MDM), which is now called Workspace ONE Unified Endpoint Management," security researchers Kristopher Russo and Chema Garcia said in an analysis. "It uses the API to establish a covert command-and-control (C2) channel, primarily through the AirWatch feature to manage custom device attributes and file uploads."
</p>

<p>
	 
</p>

<p>
	The malware, which appears in PowerShell and .NET variants, makes use of a multi-threaded command-and-control (C2) communication protocol and is capable of capturing screenshots and harvesting cookies, browser history, bookmarks, and screenshots from web browsers. It's believed that the threat actors are leveraging a stolen certificate to sign some of the artifacts.
</p>

<p>
	 
</p>

<p>
	Unit 42 said the .NET variant of Airstalk is equipped with more capabilities than its PowerShell counterpart, suggesting it could be an advanced version of the malware.
</p>

<p>
	 
</p>

<p>
	The PowerShell variant, for its part, utilizes the "/api/mdm/devices/" endpoint for C2 communications. While the endpoint is designed to fetch content details of a particular device, the malware uses the custom attributes feature in the API to use it as a dead drop resolver for storing information necessary for interacting with the attacker.
</p>

<p>
	 
</p>

<p>
	Once launched, the backdoor initializes contact by sending a "CONNECT" message and awaits a "CONNECTED" message from the server. It then receives various tasks to be executed on the compromised host in the form of a message of type "ACTIONS." The output of the execution is sent back to the threat actor using a "RESULT" message.
</p>

<p>
	 
</p>

<p>
	The backdoor supports seven different ACTIONS, including taking a screenshot, getting cookies from Google Chrome, listing all user Chrome profiles, obtaining browser bookmarks of a given profile, collecting the browser history of a given Chrome profile, enumerating all files within the user's directory, and uninstalling itself from the host.
</p>

<p>
	 
</p>

<p>
	"Some tasks require sending back a large amount of data or files after Airstalk is executed," Unit 42 said. "To do so, the malware uses the blobs feature of the AirWatch MDM API to upload the content as a new blob."
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="palo.png" class="ipsImage" data-ratio="75.10" height="540" width="610" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNW67elB0Gt2F5VUaIhJUwb5meCubbabkqfniFf88wiHCwrlmitTvwIeIxCeHQtjsqotHzA-7em7xBw3zVRTFkmWf6saf5yuuWzZytD870qFxjNk5sExdNwJJZuK_mUzr7jAW35w2PKyRcFVmxGOB4iqw4e3a0X0iRovGbknftkmhnJQ0c6foWC-NoW4nI/s2600/palo.png" />
</p>

<p>
	The .NET variant of Airstalk expands on the capabilities by also targeting Microsoft Edge and Island, an enterprise-focused browser, while attempting to mimic an AirWatch Helper utility ("AirwatchHelper.exe"). Furthermore, it supports three more message types -
</p>

<p>
	 
</p>

<ul>
	<li>
		    MISMATCH, for flagging version mismatch errors
	</li>
	<li>
		    DEBUG, for sending debug messages
	</li>
	<li>
		    PING, for beaconing
	</li>
</ul>

<p>
	 
</p>

<p>
	In addition, it uses three different execution threads, each of which serves a unique purpose: to manage C2 tasks, exfiltrate the debug log, and beacon to the C2 server. The malware also supports a broader set of commands, although one of them appears not to have been implemented yet -
</p>

<p>
	 
</p>

<ul>
	<li>
		    Screenshot, to take a screenshot
	</li>
	<li>
		    UpdateChrome, to exfiltrate a specific Chrome profile
	</li>
	<li>
		    FileMap, to list the contents of the specific directory
	</li>
	<li>
		    RunUtility (not implemented)
	</li>
	<li>
		    EnterpriseChromeProfiles, to fetch available Chrome profiles
	</li>
	<li>
		    UploadFile, to exfiltrate specific Chrome artifacts and credentials
	</li>
	<li>
		    OpenURL, to open a new URL in Chrome
	</li>
	<li>
		    Uninstall, to finish the execution
	</li>
	<li>
		    EnterpriseChromeBookmarks, to fetch Chrome bookmarks from a specific user profile
	</li>
	<li>
		    EnterpriseIslandProfiles, to fetch available Island browser profiles
	</li>
	<li>
		    UpdateIsland, to exfiltrate a specific Island browser profile
	</li>
	<li>
		    ExfilAlreadyOpenChrome, to dump all cookies from the current Chrome profile
	</li>
</ul>

<p>
	 
</p>

<p>
	Interestingly, while the PowerShell variant uses a scheduled task for persistence, its .NET version lacks such a mechanism. Unit 42 said some of the .NET variant samples are signed with a "likely stolen" certificate signed by a valid certificate authority (Aoteng Industrial Automation (Langfang) Co., Ltd.), with early iterations featuring a compilation timestamp of June 28, 2024.
</p>

<p>
	 
</p>

<p>
	It's currently not known how the malware is distributed, or who may have been targeted in these attacks. But the use of MDM-related APIs for C2 and the targeting of enterprise browsers like Island suggest the possibility of a supply chain attack targeting the business process outsourcing (BPO) sector.
</p>

<p>
	 
</p>

<p>
	"Organizations specializing in BPO have become lucrative targets for both criminal and nation-state attackers," it said. "Attackers are willing to invest generously in the resources necessary to not only compromise them but maintain access indefinitely."
</p>

<p>
	 
</p>

<p>
	"The evasion techniques employed by this malware allow it to remain undetected in most environments. This is particularly true if the malware is running within a third-party vendor's environment. This is particularly disastrous for organizations that use BPO because stolen browser session cookies could allow access to a large number of their clients."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2025/10/nation-state-hackers-deploy-new.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32200</guid><pubDate>Sat, 01 Nov 2025 10:22:17 +0000</pubDate></item><item><title>Two Windows vulnerabilities, one a 0-day, are under active exploitation</title><link>https://nsaneforums.com/news/security-privacy-news/two-windows-vulnerabilities-one-a-0-day-are-under-active-exploitation-r32192/</link><description><![CDATA[<p>
	Two Windows vulnerabilities—one a zero-day that has been known to attackers since 2017 and the other a critical flaw that Microsoft initially tried and failed to patch recently—are under active exploitation in widespread attacks targeting a swath of the Internet, researchers say.
</p>

<p>
	 
</p>

<p>
	The zero-day went undiscovered until March, when security firm Trend Micro said it had been under active exploitation since 2017, by as many as 11 separate advanced persistent threats (APTs). These APT groups, often with ties to nation-states, relentlessly attack specific individuals or groups of interest. Trend Micro went on to say that the groups were exploiting the vulnerability, then tracked as ZDI-CAN-25373, to install various known post-exploitation payloads on infrastructure located in nearly 60 countries, with the US, Canada, Russia, and Korea being the most common.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>A large-scale, coordinated operation</strong></span>
</p>

<p>
	 
</p>

<p>
	Seven months later, Microsoft still hasn’t patched the vulnerability, which stems from a bug in the Windows Shortcut binary format. The Windows component makes opening apps or accessing files easier and faster by allowing a single binary file to invoke them without having to navigate to their locations. In recent months, the ZDI-CAN-25373 tracking designation has been changed to CVE-2025-9491.
</p>

<p>
	 
</p>

<p>
	On Thursday, security firm Arctic Wolf reported that it observed a China-aligned threat group, tracked as UNC-6384, exploiting CVE-2025-9491 in attacks against various European nations. The final payload is a widely used remote access trojan known as PlugX. To better conceal the malware, the exploit keeps the binary file encrypted in the RC4 format until the final step in the attack.
</p>

<p>
	 
</p>

<p>
	“The breadth of targeting across multiple European nations within a condensed timeframe suggests either a large-scale coordinated intelligence collection operation or deployment of multiple parallel operational teams with shared tooling but independent targeting,” Arctic Wolf said. “The consistency in tradecraft across disparate targets indicates centralized tool development and operational security standards even if execution is distributed across multiple teams.”
</p>

<p>
	 
</p>

<p>
	With no patch available, Windows users are left with a limited number of options for fending off attacks. The most effective countermeasure is locking down .lnk functions by blocking or restricting the usage of .lnk files from untrusted origins. This can be done by setting the Windows Explorer to disable the automatic resolution of such files. The severity rating for CVE-2025-9491 is 7 out of 10.
</p>

<p>
	 
</p>

<p>
	The other Windows vulnerability was patched last week, when Microsoft issued an unscheduled update. CVE-2025-59287 carries a severity rating of 9.8. It resides in the Windows Server Update Services, which administrators use to install, patch, or delete apps on vast fleets of servers. Microsoft previously attempted to patch the potentially wormable remote code execution vulnerability, caused by a serialization flaw, a week earlier in its October Patch Tuesday release. Publicly released proof-of-concept code quickly proved that the attempted fix was incomplete
</p>

<p>
	 
</p>

<p>
	Around the same time that Microsoft released its second fix, security firm Huntress said it had observed the WSUS flaw being exploited starting on October 23. Security firm Eye reported the same finding shortly after.
</p>

<p>
	 
</p>

<p>
	Security firm Sophos said Wednesday that it has also observed CVE-2025-59287 being exploited “in multiple customer environments” since October 24.
</p>

<p>
	 
</p>

<p>
	“The wave of activity, which spanned several hours and targeted internet-facing WSUS servers, impacted customers across a range of industries and did not appear to be targeted attacks,” Sophos said. “It is unclear if the threat actors behind this activity leveraged the public PoC or developed their own exploit.”
</p>

<p>
	 
</p>

<p>
	Administrators should investigate immediately if their devices are vulnerable to either of the ongoing attacks. There’s no indication when Microsoft will release a patch for CVE-2025-9491.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://arstechnica.com/security/2025/10/two-windows-vulnerabilities-one-a-0-day-are-under-active-exploitation/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32192</guid><pubDate>Fri, 31 Oct 2025 23:36:56 +0000</pubDate></item><item><title>New Linux Singularity Rootkit using Sophisticated Technique to Evade Elastic EDR Detection</title><link>https://nsaneforums.com/news/security-privacy-news/new-linux-singularity-rootkit-using-sophisticated-technique-to-evade-elastic-edr-detection-r32179/</link><description><![CDATA[<p>
	A sophisticated Linux kernel rootkit designed to slip past the defenses of Elastic Security, a leading endpoint detection and response (EDR) platform.
</p>

<p>
	 
</p>

<p>
	Released on GitHub by researcher 0xMatheuZ, the rootkit employs advanced obfuscation techniques to evade YARA-based detection and behavioral monitoring.
</p>

<p>
	 
</p>

<p>
	While presented strictly for educational purposes, Singularity underscores the evolving challenges in kernel-level threat detection, potentially informing both attackers and defenders in the cybersecurity arms race.
</p>

<p>
	 
</p>

<p>
	Elastic Security, integrated with Elastic Defend, typically triggers over two dozen alerts during rootkit scans, including file quarantines and process terminations.
</p>

<p>
	 
</p>

<p>
	Singularity counters this by fragmenting its code, randomizing identifiers, and staging payloads in memory, achieving full evasion during testing.
</p>

<p>
	 
</p>

<p>
	Core capabilities include hiding processes from /proc, concealing files and directories with patterns like “singularity” or “matheuz,” masking TCP connections on port 8081, and enabling privilege escalation via custom signals or environment variables.
</p>

<p>
	 
</p>

<p>
	It also features an ICMP-based backdoor for reverse shells triggered by specific packet sequences, alongside anti-analysis measures that block tracing and sanitize logs.
</p>

<p>
	<br />
	<span><strong>Singularity Linux Rootkit Evades Elastic EDR</strong></span>
</p>

<p>
	 
</p>

<p>
	At the heart of Singularity’s success lies a multi-layered approach to static analysis evasion. Traditional rootkits falter on predictable strings and symbols that YARA rules target, such as “kallsyms_lookup_name” paired with “license=GPL” or hooks like “hook_getdents.”
</p>

<p>
	 
</p>

<p>
	<img alt="Singularity.webp" class="ipsImage" data-ratio="75.10" height="354" width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM5XWB0UFcgvz-uK7NSXdzWr4GnAnNw9mX3AbePMXhyiWyq6dzLWtG6Xv1DPoKQzYc0wcYcFIFdGC5I89DpjXukWgPsrZeOLbbLQh849RwnQGW5HSIAPaCf_5pF5Z7rxrtcj0JgEspQmjtWU6w2K2mzdLpvnFVTF18h-uZME693_L9sE9wubwKn52FUAyY/s16000/Singularity.webp" />
</p>

<p>
	<span>Singularity tool</span>
</p>

<p>
	 
</p>

<p>
	The rootkit’s Python-based obfuscator fragments these at compile-time, splitting strings into adjacent literals that the C compiler reassembles—e.g., transforming MODULE_LICENSE(“GPL”) into MODULE_LICENSE(“G” “P” “L”).
</p>

<p>
	 
</p>

<p>
	This ensures functionality while rendering the binary’s strings non-contiguous for scanners, as verified by tools like strings and objdump showing no direct matches.
</p>

<p>
	 
</p>

<p>
	Symbol name randomization takes it further, replacing suspicious prefixes (“hook_,” “fake_”) with innocuous, kernel-mimicking names like “sys_abjker_handler” or “kern_wopqls_helper.”
</p>

<p>
	 
</p>

<p>
	A whitelist protects essential kernel APIs, and regex patterns extract functions for consistent renaming, sorted by length to avoid partial substitutions, MatheuZ said.
</p>

<p>
	 
</p>

<p>
	Ftrace hooking functions, another common giveaway, receive similar treatment, renaming “fh_install_hook” to evade rules detecting two or more such patterns. These techniques collectively dismantle the 57 function-name signatures in Elastic’s generic rootkit rules.
</p>

<p>
	 
</p>

<p>
	Beyond static tricks, Singularity fragments its compiled .ko file into 64KB XOR-encoded chunks using a random 16-byte key, stored alongside metadata for reconstruction.
</p>

<p>
	 
</p>

<p>
	A custom loader, compiled statically, reassembles these in memory via memfd_create, an anonymous file descriptor that avoids disk artifacts.
</p>

<p>
	 
</p>

<p>
	It employs direct syscalls (both 64-bit and legacy 32-bit via int $0x80) to invoke finit_module, sidestepping hooked libc functions. This memory-only loading resists on-disk scanning, with fragments deletable post-execution.
</p>

<p>
	 
</p>

<p>
	Behavioral detection proves trickier, especially for the ICMP-triggered reverse shell. Elastic flags patterns like setsid with /dev/tcp/ in command lines or shell executions from kernel workers.
</p>

<p>
	 
</p>

<p>
	Singularity counters by writing a staged bash script to /singularity, hiding the spawning kworker PID immediately, then executing a clean /bin/bash /singularity.
</p>

<p>
	 
</p>

<p>
	The script opens a TCP descriptor, spawns sh in the background, and uses kill -59 on precise PIDs for targeted hiding and escalation, bypassing command-line scrutiny without affecting legitimate processes.
</p>

<p>
	 
</p>

<p>
	<img alt="Singularity%20Undetected.webp" class="ipsImage" data-ratio="47.08" height="231" width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi63NCxXlZeKS2Ij1IaY6ofVPlRkam1qelK-aN5LPVvhLOvxf4GUy6J20TFdACE6iNhfZUZjvF_k3CdumwgBFT4TQ-LcFbK3AMzFmPn4XmVmRluKBzcwy0DOiB7cVUJ6tzDaRr67zFugTtp-jnLmRwqchid9Ja_aRBN98_rgFWeSRiyd2kMFd5OeOVdobnU/s16000/Singularity%20Undetected.webp" />
</p>

<p>
	<span style="font-size:12px;">Evades security Detection</span>
</p>

<p>
	 
</p>

<p>
	Bonus evasions include compiling loaders in /tmp instead of monitored /dev/shm and automating the obfuscation pipeline for reproducibility. In tests, Singularity loaded undetected, hid processes, and established root shells, proving its mettle against current Elastic rules.
</p>

<p>
	 
</p>

<p>
	This work highlights the fragility of signature-based defenses against adaptive threats. As EDRs evolve, such research pushes for holistic detection blending machine learning and anomaly analysis. For defenders, it signals the need for deeper kernel integrity checks; for researchers, it’s a blueprint for resilience.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://cybersecuritynews.com/singularity-linux-rootkit-evades-elastic-edr/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32179</guid><pubDate>Fri, 31 Oct 2025 13:38:42 +0000</pubDate></item><item><title>CISA: High-severity Linux flaw now exploited by ransomware gangs</title><link>https://nsaneforums.com/news/security-privacy-news/cisa-high-severity-linux-flaw-now-exploited-by-ransomware-gangs-r32176/</link><description><![CDATA[<p>
	CISA confirmed on Thursday that a high-severity privilege escalation flaw in the Linux kernel is now being exploited in ransomware attacks.
</p>

<p>
	 
</p>

<p>
	While the vulnerability (tracked as CVE-2024-1086) was disclosed on January 31, 2024, as a use-after-free weakness in the netfilter: nf_tables kernel component and was fixed via a commit submitted in January 2024, it was first introduced by a decade-old commit in February 2014.
</p>

<p>
	 
</p>

<p>
	Successful exploitation enables attackers with local access to escalate privileges on the target system, potentially resulting in root-level access to compromised devices.
</p>

<p>
	 
</p>

<p>
	As Immersive Labs explains, potential impact includes system takeover once root access is gained (allowing attackers to disable defenses, modify files, or install malware), lateral movement through the network, and data theft.
</p>

<p>
	 
</p>

<p>
	In late March 2024, a security researcher using the 'Notselwyn' alias published a detailed write-up and proof-of-concept (PoC) exploit code targeting CVE-2024-1086 on GitHub, showcasing how to achieve local privilege escalation on Linux kernel versions between 5.14 and 6.6.
</p>

<p>
	 
</p>

<p>
	The flaw impacts many major Linux distributions, including but not limited to Debian, Ubuntu, Fedora, and Red Hat, which use kernel versions from 3.15 to 6.8-rc1
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Flagged as exploited in ransomware attacks</strong></span>
</p>

<p>
	 
</p>

<p>
	In a Thursday update to its catalog of vulnerabilities exploited in the wild, the U.S. cybersecurity agency said the flaw is now known to be used in ransomware campaigns, but didn't provide more information regarding ongoing exploitation attempts.
</p>

<p>
	 
</p>

<p>
	CISA added this security flaw to its Known Exploited Vulnerabilities (KEV) catalog in May 2024 and ordered federal agencies to secure their systems by June 20, 2024.
</p>

<p>
	 
</p>

<p>
	If patching is not possible, IT admins are advised to apply one of the following mitigations:
</p>

<p>
	 
</p>

<ol>
	<li>
		    Blocklist 'nf_tables' if it's not needed/actively used,
	</li>
	<li>
		    Restrict access to user namespaces to limit the attack surface,
	</li>
	<li>
		    Load the Linux Kernel Runtime Guard (LKRG) module (however, this can cause system instability).
	</li>
</ol>

<p>
	 
</p>

<p>
	"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said. "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.bleepingcomputer.com/news/security/cisa-linux-privilege-escalation-flaw-now-exploited-in-ransomware-attacks/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32176</guid><pubDate>Fri, 31 Oct 2025 13:22:14 +0000</pubDate></item><item><title>&#x2018;Dangerous&#x2019; YouTube videos struck down for bypassing Windows 11 account setup</title><link>https://nsaneforums.com/news/security-privacy-news/%E2%80%98dangerous%E2%80%99-youtube-videos-struck-down-for-bypassing-windows-11-account-setup-r32169/</link><description><![CDATA[<p>
	<span>A creator had two Windows guides taken down by YouTube's automated systems, allegedly in violation of the "harmful or dangerous content policy." </span>
</p>

<p>
	 
</p>

<p>
	Microsoft, really, really, really wants you to log in with a full, connected Microsoft account for Windows 11. It’s essential for tracking user data, feeding people ads, and generally making your PC experience much more frustrating (though it also enables ease-of-life features like OneDrive and account syncing between PCs). Users have been finding ways around this requirement for a while, and sharing their results. This is apparently a “harmful or dangerous” act, according to YouTube.
</p>

<p>
	 
</p>

<p>
	That’s the inescapable conclusion one must draw from the fact that YouTube creator CyberCPU Tech has reportedly had a video on this topic removed from the platform, and all appeals to YouTube and Google have been denied, according to the creator. The same thing happened a week later for a guide on how to install Windows 11 25H2 on older, unsupported hardware, as reported by Tom’s Hardware. Both videos were flagged by YouTube’s automated system as a violation of its “Harmful or dangerous content policy.” Again, when the creator asked for a manual review, the appeal was denied.
</p>

<p>
	 
</p>

<p>
	YouTube’s policy outlaws obvious things like “instructional theft” (piracy, defeating retail store theft prevention, etc), “hacking” with the intent to steal information, bypassing payment systems, and phishing. I haven’t seen the videos, of course — they’re gone. But as far as I can tell, none of CyberCPU’s instructions would have included any of this, assuming it was just telling people how to install Windows 11 on older hardware or install it without a connected user account, something Windows has been able to do for decades.
</p>

<p>
	 
</p>

<p>
	According to the policy, a channel that gets three such strikes in a 90-day period can be terminated permanently. CyberCPU says that only one strike was applied to the channel, with the second video included in the original warning.
</p>

<p>
	 
</p>

<p>
	The CyberCPU Tech channel is five years old and has 300,000 subscribers, which is considered mid-range for the platform, but many creators make a living from channels that size. After taking a class provided by YouTube, the channel will be in good standing with the platform by January 2026, and the creator has applied to get a personal representative assigned from YouTube.
</p>

<p>
	 
</p>

<p>
	In a follow-up video posted two days ago, CyberCPU Tech claims that the second appeal was denied in less than a minute. Other YouTube creators that have covered similar Windows topics have also had their videos removed, according to yet another video from the channel. While they didn’t initially believe that Microsoft had anything to do with the takedowns, instead blaming YouTube’s “AI-enhanced” and notoriously unreliable automated system, they now think otherwise. “In fact, I believe they [Microsoft] are entirely responsible for this.”
</p>

<p>
	 
</p>

<p>
	After outlining alternative video options, the creator said, “Are we not allowed to make videos about installing Windows on unsupported hardware because of some backroom deal with Microsoft? If that’s the case, then Microsoft’s own website shows how to do it. But fine, we won’t make those videos anymore, we just need to know the rules and make them clear.”
</p>

<p>
	 
</p>

<p>
	No evidence for direct Microsoft involvement was offered, though YouTube’s labyrinthian processes for creators aren’t helping to assuage those fears. Copyright strikes, a separate but easily exploitable system, are often used by IP owners to shut down unfavorable YouTube videos even when they clearly fall under fair use. YouTube channel operators have to navigate an inscrutable system that offers little to no guidance on what specific part of a video constitutes a violation, whether actions were taken automatically or due to reports from viewers or third parties, and how they might avoid getting strikes in the future.
</p>

<p>
	 
</p>

<p>
	CyberCPU Tech intends to continue making videos on similar Windows topics, though they may be posted elsewhere. The creator mentioned X/Twitter, Floatplane, a tech-focused platform owned and operated by Linus Media Group (owner of Linus Tech Tips), and Rumble, an alternative video site made for right-wing influencers. Rumble provides hosting for U.S. President Trump’s personal social network Truth Social, and is popular with influencers who have been banned from more mainstream platforms, like game streamer “Dr Disrespect” and alleged human trafficker Andrew Tate.
</p>

<p>
	 
</p>

<p>
	The creator said that Rumble is not a realistic option for tech creators who want to move off YouTube. “…After two years and hundreds of videos, I’ve made a total of 43 cents.” Non-political content on YouTube alternatives struggles to maintain viewers (though more generalized competitors like TikTok and Instagram Reels are faring better). “But as long as people continue to upload to YouTube,” says CyberCPU, “YouTube will still be able to abuse their creators, because they have no incentive not to.”
</p>

<p>
	 
</p>

<p>
	Whether automated or guided by human hands, YouTube’s policies continue to frustrate many of the creators who make the platform successful. Regular viewers are also becoming tired of the site’s many problems, including rising prices for ad-free viewing and a massive influx of AI slop, much of which is provided by YouTube itself. Even as the platform gets measurably worse in many different ways and faces increasing competition from services like TikTok, it remains the de facto home of user-uploaded video on the web. 
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.pcworld.com/article/2957554/dangerous-youtube-videos-struck-down-for-bypassing-windows-11-account-setup.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32169</guid><pubDate>Fri, 31 Oct 2025 01:00:57 +0000</pubDate></item><item><title>Malicious NPM packages fetch infostealer for Windows, Linux, macOS</title><link>https://nsaneforums.com/news/security-privacy-news/malicious-npm-packages-fetch-infostealer-for-windows-linux-macos-r32147/</link><description><![CDATA[<p>
	Ten malicious packages mimicking legitimate software projects in the npm registry download an information-stealing component that collects sensitive data from Windows, Linux, and macOS systems.
</p>

<p>
	 
</p>

<p>
	The packages were uploaded to npm on July 4, and remained undetected for a long period due to multiple layers of obfuscation that helped escape standard static analysis mechanisms.
</p>

<p>
	 
</p>

<p>
	According to researchers at cybersecurity company Socket, the ten packages counted nearly 10,000 downloads and stole credentials from system keyrings, browsers, and authentication services.
</p>

<p>
	 
</p>

<p>
	At the time of writing, the packages are still available, despite Socket reporting them to npm:
</p>

<p>
	 
</p>

<ol>
	<li>
		typescriptjs
	</li>
	<li>
		deezcord.js
	</li>
	<li>
		dizcordjs
	</li>
	<li>
		dezcord.js
	</li>
	<li>
		etherdjs
	</li>
	<li>
		ethesjs
	</li>
	<li>
		ethetsjs
	</li>
	<li>
		nodemonjs
	</li>
	<li>
		react-router-dom.js
	</li>
	<li>
		zustand.js
	</li>
</ol>

<p>
	 
</p>

<p>
	Socket <a href="http://socket.dev/blog/10-npm-typosquatted-packages-deploy-credential-harvester" rel="external nofollow" target="_blank">researchers say</a> that the packages use a fake CAPTCHA challenge to appear legitimate and download a 24MB infostealer packaged with PyInstaller.
</p>

<p>
	 
</p>

<p>
	To lure users, the threat actor used typosquatting, a tactic that leverages misspellings or variations of the legitimate names for TypeScript (typed superset of JavaScript), discord.js (Discord bot library), ethers.js (Ethereum JS library), nodemon (auto-restarts Node apps), react-router-dom (React browser router), and zustand (minimal React state manager).
</p>

<p>
	 
</p>

<p>
	When searching for the legitimate packages on the npm platform, developers may mistype the name of the legitimate package or pick a malicious one listed in the results.
</p>

<p>
	 
</p>

<p>
	Upon installation, a ‘postinstall’ script is triggered automatically to spawn a new terminal that matches the host’s detected OS. The script executes ‘app.js’ outside the visible install log and clears the window immediately to evade detection.
</p>

<p>
	 
</p>

<p>
	The ‘app.js’ file is the malware loader which employs four obfuscation layers: self-decoding eval wrapper, XOR decryption with dynamically generated key, URL-encoded payload, and heavy control-flow obfuscation.
</p>

<p>
	 
</p>

<p>
	The script displays a fake CAPTCHA in the terminal using ASCII to give false legitimacy to the installation process.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Fake ASCII CAPTCHA step" class="ipsImage" height="465" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/October/ascii-captcha.jpg">
		<figcaption>
			<em>Bogus ASCII CAPTCHA step<br>
			Source: Socket</em>
		</figcaption>
	</figure>
</div>

<p>
	Next, it sends the victim's geolocation and system fingerprint information to the attacker's command and control (C2) server. Having acquired this information, the malware downloads and automatically launches a platform-specific binary from an external source, which is a 24 MB PyInstaller-packaged executable.
</p>

<p>
	 
</p>

<p>
	The information stealer targets system keyrings such as Windows Credential Manager, macOS Keychain, Linux SecretService, libsecret, and KWallet, as well as data stored in Chromium-based and Firefox browsers, including profiles, saved passwords, and session cookies.
</p>

<p>
	 
</p>

<p>
	Moreover, it seeks SSH keys in common directories, and also attempts to locate and steal OAuth, JWT, and other API tokens.
</p>

<p>
	 
</p>

<p>
	The stolen information is packaged into compressed archives and exfiltrated to the attacker’s server at 195[.]133[.]79[.]43, following a temporary staging step in /var/tmp or /usr/tmp.
</p>

<p>
	 
</p>

<p>
	Developers who downloaded any of the listed packages are recommended to clean up the infection and rotate all access tokens and passwords, as there is a good chance that they are compromised.
</p>

<p>
	 
</p>

<p>
	When sourcing packages from npm or other open-source indexes, it is advisable to double-check for typos and ensure that everything comes from reputable publishers and official repositories.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/malicious-npm-packages-fetch-infostealer-for-windows-linux-macos/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 30 October 2025 at 12:11 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32147</guid><pubDate>Thu, 30 Oct 2025 02:12:33 +0000</pubDate></item><item><title>Google Chrome to warn users before opening insecure HTTP sites</title><link>https://nsaneforums.com/news/security-privacy-news/google-chrome-to-warn-users-before-opening-insecure-http-sites-r32107/</link><description><![CDATA[<p>
	Google announced today that the Chrome web browser will start warning users by default before connecting to insecure HTTP public websites beginning with Chrome 154 in October 2026.
</p>

<p>
	 
</p>

<p>
	Google Chrome also has an <a href="https://www.bleepingcomputer.com/news/security/google-chrome-will-add-https-first-mode-to-keep-your-data-safe/" rel="external nofollow" target="_blank">opt-in HTTPS-First Mode</a> since 2021, which added the "Always Use Secure Connections" setting and attempts to connect to websites over HTTPS (HyperText Transfer Protocol Secure), displaying a bypassable warning if HTTPS is unavailable.
</p>

<p>
	 
</p>

<p>
	However, Google will now enable this option by default to ensure that users visit websites only via HTTPS and are always protected from man-in-the-middle (MITM) attacks that try to snoop on or alter data exchanged with Internet servers over the unencrypted HTTP protocol.
</p>

<p>
	 
</p>

<p>
	"One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable 'Always Use Secure Connections.' This means Chrome will ask for the user's permission before the first access to any public site without HTTPS," the company said.
</p>

<p>
	 
</p>

<p>
	"When links don't use HTTPS, an attacker can hijack the navigation and force Chrome users to load arbitrary, attacker-controlled resources, and expose the user to malware, targeted exploitation, or social engineering attacks."
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="HTTP warning" class="ipsImage" height="364" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/HTTP-warning.png">
		<figcaption>
			<em>HTTP warning (Google)</em>
		</figcaption>
	</figure>
</div>

<p>
	As Google further explained, across all variants of the "Always Use Secure Connections" settings (targeting private or public websites), Chrome will not repeatedly warn the user about that site as long as the user regularly visits an insecure site. This means that rather than warn users about 1 out of 50 navigations, Chrome will only warn users when they open a new (or rarely visited) site that doesn't use HTTPS.
</p>

<p>
	 
</p>

<p>
	Additionally, users will have the option to enable insecure connection alerts for public sites only or for both public and private sites (including enterprise intranets).
</p>

<p>
	 
</p>

<p>
	It's important to note that while private sites can still be risky, they are generally considered less dangerous than public sites because there are fewer opportunities for attackers to exploit them, and HTTP can only be misused by attackers within a more limited context, such as a local network like your home Wi-Fi or within a corporate environment.
</p>

<p>
	 
</p>

<p>
	However, even with both types of warnings toggled on, users shouldn't be bombarded with notifications, seeing that around 95-99% of all websites have adopted HTTPS, a massive increase from 2015's adoption rate of roughly 30-45%.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Secure connection settings" class="ipsImage" height="275" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Secure%20connection%20settings.png">
		<figcaption>
			<em>Secure connection settings (Google)</em>
		</figcaption>
	</figure>
</div>

<p>
	Before enabling it by default for all users, Chrome will enable "Always Use Secure Connections" for public sites for over 1 billion users using Enhanced Safe Browsing protections in April 2026, when Chrome 147 will be released.
</p>

<p>
	 
</p>

<p>
	"While it is our hope and expectation that this transition will be relatively painless for most users, users will still be able to disable the warnings by disabling the 'Always Use Secure Connections' setting," Google added.
</p>

<p>
	 
</p>

<p>
	"If you are a website developer or IT professional, and you have users who may be impacted by this feature, we very strongly recommend enabling the 'Always Use Secure Connections' setting today to help identify sites that you may need to work to migrate."
</p>

<p>
	 
</p>

<p>
	In October 2023, Google Chrome <a href="https://www.bleepingcomputer.com/news/google/google-chrome-now-auto-upgrades-to-secure-connections-for-all-users/" rel="external nofollow" target="_blank">added an HTTPS-Upgrades feature</a> that automatically upgrades in-page HTTP links to secure connections for all users, while ensuring a quick fallback to HTTP if needed.
</p>

<p>
	 
</p>

<p>
	Earlier this month, Google also updated its web browser again to <a href="https://www.bleepingcomputer.com/news/google/google-chrome-to-revoke-notification-access-for-inactive-sites/" rel="external nofollow" target="_blank">automatically revoke notification permissions</a> for sites that haven't been visited recently, to reduce alert overload.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/google/google-chrome-to-warn-users-before-opening-insecure-http-sites/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 29 October 2025 at 3:49 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32107</guid><pubDate>Tue, 28 Oct 2025 17:50:25 +0000</pubDate></item><item><title>Google disputes false claims of massive Gmail data breach</title><link>https://nsaneforums.com/news/security-privacy-news/google-disputes-false-claims-of-massive-gmail-data-breach-r32101/</link><description><![CDATA[<p>
	Google was once again forced to announce that it had not suffered a data breach after <a href="http://www.google.com/search?q=gmail+data+breach&amp;tbm=nws" rel="external nofollow" target="_blank">numerous news outlets</a> published sensational stories about a fake breach that purportedly exposed 183 million accounts.
</p>

<p>
	 
</p>

<p>
	This claim began over the weekend and into today, with news stories claiming that millions of Gmail accounts were breached, with some outlets saying it affected the full 183 million accounts.
</p>

<p>
	 
</p>

<p>
	However, as the company explained in a series of posts on Monday, Gmail did not suffer a breach, and the compromised accounts were actually from a compilation of credentials stolen by information-stealing malware and other attacks over the years.
</p>

<p>
	 
</p>

<p>
	"Reports of a 'Gmail security breach impacting millions of users' are false. Gmail's defenses are strong, and users remain protected," <a href="https://x.com/NewsFromGoogle/status/1982893232934793655" rel="external nofollow" target="_blank">reads a post on X</a>.
</p>

<p>
	 
</p>

<p>
	"The inaccurate reports are stemming from a misunderstanding of infostealer databases, which routinely compile various credential theft activity occurring across the web. It's not reflective of a new attack aimed at any one person, tool, or platform."
</p>

<p>
	 
</p>

<p>
	"Several inaccurate claims surfaced recently that incorrectly stated that we issued a broad warning to all Gmail users about a major Gmail security issue. This is entirely false," Google added.
</p>

<p>
	 
</p>

<p>
	This is just the latest such story that numerous news websites and cybersecurity companies have reported without verification in recent years.
</p>

<p>
	 
</p>

<p>
	This particular story stems from Have I Been Pwned (HIBP) creator <a href="http://www.troyhunt.com/inside-the-synthient-threat-data/" rel="external nofollow" target="_blank">Troy Hunt announcing</a> he recently added a massive collection of 183 million compromised credentials to the data breach notification platform shared by the threat intelligence platform Synthient.
</p>

<p>
	 
</p>

<p>
	These credentials were not stolen in a single data breach, but rather through information-stealing malware, data breaches, credential stuffing, and phishing. Furthermore, these accounts are not for a single platform but for thousands, if not millions, of sites.
</p>

<p>
	 
</p>

<p>
	Threat actors commonly collect exposed credentials and combine them into massive collections, which are then shared among the cybercrime community on Telegram channels, Discord servers, and hacking forums.
</p>

<p>
	 
</p>

<p>
	After loading the data into HIBP, Hunt says 91% of the 183 million credentials had previously been seen, illustrating that many of them have been circulating for years.
</p>

<p>
	 
</p>

<p>
	"The final number once the entire data set was loaded into HIBP was 91% pre-existing, with 16.4M previously unseen addresses in <em>any </em>data breach, not just stealer logs," explained Hunt.
</p>

<p>
	 
</p>

<p>
	Companies, including Google, commonly use collections like these to warn customers of exposed passwords and to force password resets to protect accounts.
</p>

<p>
	 
</p>

<p>
	"Gmail takes action when we spot large batches of open credentials, helping users reset passwords and resecure accounts," explained Google.
</p>

<p>
	 
</p>

<p>
	While the claims of a Gmail data breach are false, that does not mean exposed credentials are harmless or should be ignored, as threat actors commonly use them to breach corporate networks and carry out devastating attacks.
</p>

<p>
	 
</p>

<p>
	For example, the UnitedHealth Change Healthcare ransomware attack was caused by <a href="https://www.bleepingcomputer.com/news/security/change-healthcare-hacked-using-stolen-citrix-account-with-no-mfa/" rel="external nofollow" target="_blank">exposed Citrix credentials</a> that enabled threat actors to gain initial network access.
</p>

<p>
	 
</p>

<p>
	However, reports of unfounded data breaches do not help anyone and only cause undue stress and extra work for a platform's users and business customers.
</p>

<p>
	 
</p>

<p>
	Just last month, Google had to state that it did not suffer a data breach after the same news sites <a href="https://www.bleepingcomputer.com/news/technology/no-google-did-not-warn-25-billion-gmail-users-to-reset-passwords/" rel="external nofollow" target="_blank">claimed that 2.5 billion Gmail accounts had been compromised</a>.
</p>

<p>
	 
</p>

<p>
	While that claim stemmed from a Salesloft breach that impacted a <a href="https://www.bleepingcomputer.com/news/security/google-warns-salesloft-breach-impacted-some-workspace-accounts/" rel="external nofollow" target="_blank">small number of Google Workspace accounts</a>, the story was quickly sensationalized into a much larger breach.
</p>

<p>
	 
</p>

<p>
	If you are concerned that your credentials may have been part of the Synthient collection, you can register an account at <a href="https://haveibeenpwned.com/" rel="external nofollow" target="_blank">Have I Been Pwned</a>, open the dashboard, and click Stealer Logs to see if your account was compromised in the past by information-stealing malware.
</p>

<p>
	 
</p>

<p>
	If you have accounts listed, perform an antivirus scan on your computer, then immediately change the passwords for all of your accounts.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-disputes-false-claims-of-massive-gmail-data-breach/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 28 October 2025 at 12:57 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32101</guid><pubDate>Tue, 28 Oct 2025 02:58:40 +0000</pubDate></item><item><title>Ransomware profits drop as victims stop paying hackers</title><link>https://nsaneforums.com/news/security-privacy-news/ransomware-profits-drop-as-victims-stop-paying-hackers-r32099/</link><description><![CDATA[<p>
	The number of victims paying ransomware threat actors has reached a new low, with just 23% of the breached companies giving in to attackers' demands.
</p>

<p>
	 
</p>

<p>
	With some exceptions, the decline in payment resolution rates continues the trend that Coveware has observed for the past six years.
</p>

<p>
	 
</p>

<p>
	In the first quarter of 2024, the payment percentage <a href="https://www.bleepingcomputer.com/news/security/ransomware-payments-drop-to-record-low-of-28-percent-in-q1-2024/" rel="external nofollow" target="_blank">was 28%</a>. Although it increased over the next period, it continued to drop, reaching an all-time low in the third quarter of 2025.
</p>

<p>
	 
</p>

<p>
	One explanation for this is that organizations implemented stronger and more targeted protections against ransomware, and authorities increasing pressure for victims not to pay the hackers.
</p>

<p>
	 
</p>

<p>
	“Cyber defenders, law enforcement, and legal specialists should view this as validation of collective progress,” <a href="https://www.coveware.com/blog/2025/10/24/insider-threats-loom-while-ransom-payment-rates-plummet" rel="external nofollow" target="_blank">Coveware says</a>.
</p>

<p>
	 
</p>

<p>
	“The work that gets put in to prevent attacks, minimize the impact of attacks, and successfully navigate a cyber extortion — each avoided payment constricts cyber attackers of oxygen.”
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Percentage of ransom payments over time" class="ipsImage" height="284" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/October/payment+rate.jpg">
		<figcaption>
			<em>Percentage of ransom payments over time<br>
			Source: Coveware</em>
		</figcaption>
	</figure>
</div>

<p>
	Over the years, ransomware groups moved from pure encryption attacks to double extortion that came with data theft and the threat of a public leak.
</p>

<p>
	 
</p>

<p>
	Coveware reports that more than 76% of the attacks it observed in Q3 2025 involved data exfiltration, which is now the primary objective for most ransomware groups.
</p>

<p>
	 
</p>

<p>
	The company says that when it isolates the attacks that do not encrypt the data and only steal it, the payment rate plummets to 19%, which is also a record for that sub-category.
</p>

<p>
	 
</p>

<p>
	The average and median ransomware payments fell in Q3 compared to the previous quarter, reaching $377,000 and $140,000, respectively, according to Coveware.
</p>

<p>
	 
</p>

<p>
	The shift may reflect large enterprises revising their ransom payment policies and recognizing that those funds are better spent on strengthening defenses against future attacks.
</p>

<p>
	 
</p>

<p>
	The researchers also note that threat groups like Akira and Qilin, which accounted for 44% of all recorded attacks in Q3 2025, have switched focus to medium-sized firms that are currently more likely to pay a ransom.
</p>

<p>
	 
</p>

<p>
	Another notable trend over the past year is the rise of remote access compromise as the leading attack vector, alongside a significant increase in the use of software vulnerabilities.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Initial access vectors in Q3 2025" class="ipsImage" height="435" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/October/vectors.jpg">
		<figcaption>
			<em>Initial access vectors in Q3 2025<br>
			Source: Coveware</em>
		</figcaption>
	</figure>
</div>

<p>
	Coveware believes that diminishing profits are driving ransomware gangs to greater precision and that larger enterprises will be increasingly targeted as profit margins continue to shrink.
</p>

<p>
	 
</p>

<p>
	As larger organizations have strengthened their security posture, threat actors are likely to rely more on social engineering and <a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-sought-bbc-reporters-help-in-hacking-media-giant/" rel="external nofollow" target="_blank">insider recruitment</a>, offering large bribes for help gaining initial access.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/ransomware-profits-drop-as-victims-stop-paying-hackers/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 28 October 2025 at 12:54 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32099</guid><pubDate>Tue, 28 Oct 2025 02:55:45 +0000</pubDate></item><item><title>10M people watched a YouTuber shim a lock; the lock company sued him. Bad idea.</title><link>https://nsaneforums.com/news/security-privacy-news/10m-people-watched-a-youtuber-shim-a-lock-the-lock-company-sued-him-bad-idea-r32092/</link><description><![CDATA[<h3>
	It’s still legal to pick locks, even when you swing your legs.
</h3>

<p>
	“Opening locks” might not sound like scintillating social media content, but Trevor McNally has turned lock-busting into online gold. A former US Marine Staff Sergeant, McNally today has more than 7 million followers and has amassed more than 2 billion views just by showing how easy it is to open many common locks by slapping, picking, or shimming them.
</p>

<p>
	 
</p>

<p>
	This does not always endear him to the companies that make the locks.
</p>

<p>
	 
</p>

<p>
	On March 3, 2025, a Florida lock company called Proven Industries released a social media promo video just begging for the McNally treatment. The video was called, somewhat improbably, “YOU GUYS KEEP SAYING YOU CAN EASILY BREAK OFF OUR LATCH PIN LOCK.” In it, an enthusiastic man in a ball cap says he will “prove a lot of you haters wrong.” He then goes hard at Proven’s $130 model 651 trailer hitch lock with a sledgehammer, bolt cutters, and a crowbar.
</p>

<p>
	 
</p>

<p>
	Naturally, the lock hangs tough.
</p>

<p>
	 
</p>

<p>
	An Instagram user brought the lock to McNally’s attention by commenting, “Let’s introduce it to the @mcnallyofficial poke.” Someone from Proven responded, saying that McNally only likes “the cheap locks lol because they are easy and fast.” Proven locks were said to be made of sterner stuff.
</p>

<p>
	 
</p>

<p>
	But on April 3, McNally posted a <a href="https://www.youtube.com/shorts/YjzlmKz_MM8" rel="external nofollow">saucy little video</a> to social media platforms. In it, he watches the Proven promo video while swinging his legs and drinking a Juicy Juice. He then hops down from his seat, goes over to a Proven trailer hitch lock, and opens it in a matter of seconds using nothing but a shim cut from a can of <a href="https://liquiddeath.com" rel="external nofollow">Liquid Death</a>. He says nothing during the entire video, which has been viewed nearly 10 million times on YouTube alone.
</p>

<p>
	 
</p>

<p>
	Despite practically begging people to attempt this, Proven Industries owner Ron Lee contacted McNally on Instagram. “Just wanted to say thanks and be prepared!” he wrote. McNally took this as a threat.
</p>

<p>
	 
</p>

<p>
	(Oddly enough, Proven’s own homepage <a href="https://www.youtube.com/watch?v=gIajKFBtq28&amp;t=3s" rel="external nofollow">features a video</a> in which the company trashes competing locks and shows just how easy it is to defeat them. And its news pages contain <a href="https://www.provenlocks.com/blogs/news/master-lock-failure-reasons" rel="external nofollow">articles</a> and videos on “The Hidden Flaws of Master Locks” and other brands. Why it got so upset about McNally’s video is unclear.)
</p>

<p>
	 
</p>

<p>
	The next day, Lee texted McNally’s wife. The message itself was apparently Lee’s attempt to de-escalate things; he says he thought the number belonged to McNally, and the message itself was unobjectionable. But after the “be prepared!” notice of the day before, and given the fact that Lee already knew how to contact him on Instagram, McNally saw the text as a way “to intimidate me and my family.” That feeling was cemented when McNally found out that Lee was a triple felon—and that in one case, Lee had hired someone “to throw a brick through the window of his ex-wife.”
</p>

<p>
	 
</p>

<p>
	Concerned about losing business, Lee kept trying to shut McNally down. Proven posted a “<a href="https://www.youtube.com/shorts/16nZqtT-1sI" rel="external nofollow">response video</a>” on April 6 and engaged with numerous social media commenters, telling them that things were “going to get really personal” for McNally. Proven employees alleged publicly that McNally was deceiving people about all the prep work he had done to make a “perfectly cut out” shim. Without extensive experience, long prep work, and precise measurements, it was said, Proven’s locks were in little danger of being opened by rogue actors trying to steal your RV.
</p>

<p>
	 
</p>

<p>
	“Sucks to see how many people take everything they see online for face value,” one Proven employee wrote. “Sounds like a bunch of liberals lol.”
</p>

<p>
	 
</p>

<p>
	Proven also had its lawyers file “multiple” DMCA takedown notices against the McNally video, claiming that its use of Proven’s promo video was copyright infringement.
</p>

<p>
	 
</p>

<p>
	McNally didn’t bow to the pressure, though, instead uploading several more videos showing him opening Proven locks. In <a href="https://www.youtube.com/shorts/MbQp5JcQwLA" rel="external nofollow">one of them</a>, he takes aim at Proven’s claims about his prep work by retrieving a new lock from an Amazon delivery kiosk, taking it outside—and popping it in seconds using a shim he cuts right on camera, with no measurements, from an aluminum can.
</p>

<div class="ars-subscribe-shortcode">
	 
</div>

<p>
	On May 1, Proven filed a federal lawsuit against McNally in the Middle District of Florida, charging him with a huge array of offenses: (1) copyright infringement, (2) defamation by implication, (3) false advertising, (4) violating the Florida Deceptive and Unfair Trade Practices Act, (5) tortious interference with business relationships, (6) unjust enrichment, (7) civil conspiracy, <em>and</em> (8) trade libel. Remarkably, the claims stemmed from a video that all sides admit was accurate and in which McNally himself said nothing.
</p>

<figure class="ars-wp-img-shortcode id-2124130 align-center">
	<div>
		<img alt="Screenshot of a social media exchange." class="center medium" decoding="async" height="383" loading="lazy" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-640x383.jpg 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-1024x613.jpg 1024w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-768x460.jpg 768w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-1536x920.jpg 1536w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-980x587.jpg 980w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-1440x862.jpg 1440w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks.jpg 1954w" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2025/10/they-like-cheap-locks-640x383.jpg">
	</div>

	<figcaption>
		<div class="caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300">
			<div class="caption-icon bg-[left_top_5px] w-[10px] shrink-0">
				 
			</div>

			<div class="caption-content">
				<em>In retrospect, this was probably not a great idea. </em>
			</div>
		</div>
	</figcaption>
</figure>

<h2>
	Don’t mock me, bro
</h2>

<p>
	How can you defame someone without even speaking? Proven claimed “defamation by implication,” arguing that the whole setup of McNally’s videos was unfair to the company and its product. McNally does not show his prep work, which (Proven argued) conveys to the public the false idea that Proven’s locks are easy to bypass. While the shimming does work, Proven argued that it would be difficult for an untrained user to perform.
</p>

<p>
	 
</p>

<p>
	But what Proven really, <em>really</em> didn’t like was being mocked. McNally’s decision to drink—and shake!—a juice box on video comes up in court papers a mind-boggling number of times. Here’s a sample:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		McNally appears swinging his legs and sipping from an apple juice box, conveying to the purchasing public that bypassing Plaintiff’s lock is simple, trivial, and even comical…
	</p>

	<p>
		 
	</p>

	<p>
		…showing McNally drinking from, and shaking, a juice box, all while swinging his legs, and displaying the Proven Video on a mobile device…
	</p>

	<p>
		 
	</p>

	<p>
		The tone, posture, and use of the juice box prop and childish leg swinging that McNally orchestrated in the McNally Video was intentional to diminish the perceived seriousness of Proven Industries…
	</p>

	<p>
		 
	</p>

	<p>
		The use of juvenile imagery, such as sipping from a juice box while casually applying the shim, reinforces the misleading impression that the lock is inherently insecure and marketed deceptively…
	</p>

	<p>
		 
	</p>

	<p>
		The video then abruptly shifts to Defendant in a childlike persona, sipping from a juice box and casually applying a shim to the lock…
	</p>
</blockquote>

<p>
	In the end, Proven argued that the McNally video was “for commercial entertainment and mockery,” produced for the purpose of “humiliating Plaintiff.” McNally, it was said, “will not stop until he destroys Proven’s reputation.” Justice was needed. Expensive, litigious justice.
</p>

<p>
	 
</p>

<p>
	But the proverbially level-headed horde of Internet users does not always love it when companies file thermonuclear lawsuits against critics. Sometimes, in fact, the level-headed horde disregards everything taught by that fount of judicial knowledge, <a href="https://en.wikipedia.org/wiki/The_People%27s_Court" rel="external nofollow"><em>The People’s Court</em></a>, and they take the law into their own hands.
</p>

<p>
	 
</p>

<p>
	Proven was soon the target of McNally fans. The company says it was “forced to disable comments on posts and product videos due to an influx of mocking and misleading replies furthering the false narrative that McNally conveyed to the viewers.” The company’s customer service department received such an “influx of bogus customer service tickets… that it is experiencing difficulty responding to legitimate tickets.”
</p>

<figure class="ars-wp-img-shortcode id-2124129 align-center">
	<div>
		<img alt="Screenshot of a social media post from Proven Industries." class="center medium" decoding="async" height="561" loading="lazy" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/10/fooling-people-for-years-640x561.jpg 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/10/fooling-people-for-years.jpg 660w" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2025/10/fooling-people-for-years-640x561.jpg">
	</div>

	<figcaption>
		<div class="caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300">
			<div class="caption-content">
				<em>Proven was quite proud of its lawsuit… at first. </em>
			</div>
		</div>
	</figcaption>
</figure>

<p>
	Someone posted Lee’s personal phone number to the comment section of a McNally video, which soon led to “a continuous stream of harassing phone calls and text messages from unknown numbers at all hours of the day and night,” which included “profanity, threats, and racially charged language.”
</p>

<p>
	 
</p>

<p>
	Lest this seem like mere high spirits and hijinks, Lee’s partner and his mother both “received harassing messages through Facebook Messenger,” while other messages targeted Lee’s son, saying things like “I would kill your f—ing n—– child” and calling him a “racemixing pussy.”
</p>

<p>
	 
</p>

<p>
	This is clearly terrible behavior; it also has no obvious connection to McNally, who did not direct or condone the harassment. As for Lee’s phone number, McNally said that he had nothing to do with posting it and wrote that “it is my understanding that the phone number at issue is publicly available on the Better Business Bureau website and can be obtained through a simple Google search.”
</p>

<p>
	 
</p>

<p>
	And this, with both sides palpably angry at each other, is how things stood on June 13 at 9:09 am, when the case got a hearing in front of the Honorable Mary Scriven, an extremely feisty federal judge in Tampa. Proven had demanded a preliminary injunction that would stop McNally from sharing his videos while the case progressed, but Proven had issues right from the opening gavel:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		<strong>LAWYER 1:</strong> Austin Nowacki on behalf of Proven industries.<br>
		<strong>THE COURT:</strong> I’m sorry. What is your name?<br>
		<strong>LAWYER 1:</strong> Austin Nowacki.<br>
		<strong>THE COURT:</strong> I thought you said Austin No Idea.<br>
		<strong>LAWYER 2:</strong> That’s Austin Nowacki.<br>
		<strong>THE COURT</strong>: All right.
	</p>
</blockquote>

<p>
	When Proven’s lead lawyer introduced a colleague who would lead that morning’s arguments, the judge snapped, “Okay. Then you have a seat and let her speak.”
</p>

<p>
	 
</p>

<p>
	Things went on this way for some time, as the judge wondered, “Did the plaintiff bring a lock and a beer can?” (The plaintiff did not.) She appeared to be quite disappointed when it was clear there would be no live shimming demonstration in the courtroom.
</p>

<p>
	 
</p>

<p>
	Then it was on to the actual arguments. Proven argued that the 15 seconds of its 90-second promo video used by McNally were not fair use, that McNally had defamed the company by implication, and that shimming its locks was actually quite difficult. Under questioning, however, one of Proven’s employees admitted that he had been able to duplicate McNally’s technique, leading to the question from McNally’s lawyer: “When you did it yourself, did it occur to you for one moment that maybe the best thing to do, instead of file a lawsuit, was to fix [the lock]?”
</p>

<p>
	 
</p>

<p>
	At the end of several hours of wrangling, the judge stepped in, saying that she “declines to grant the preliminary injunction motion.” For her to do so, Proven would have to show that it was likely to win at trial, among other things; it had not.
</p>

<p>
	 
</p>

<p>
	As for the big copyright infringement claim, of which Proven had made so much hay, the judge reached a pretty obvious finding: You’re allowed to quote snippets of copyrighted videos in order to critique them.
</p>

<p>
	 
</p>

<p>
	“The purpose and character of the use to which Mr. McNally put the alleged infringed work is transformative, artistic, and a critique,” said the judge. “He is in his own way challenging and critiquing Proven’s video by the use of his own video.”
</p>

<p>
	 
</p>

<p>
	As for the amount used, it was “substantial enough but no more than is necessary to make the point that he is trying to critique Proven’s video, and I think that’s fair game and a nominative fair use circumstance.”
</p>

<p>
	 
</p>

<p>
	While Proven <em>might</em> convince her otherwise after a full trial, “the copyright claim fails as a basis for a demand for preliminary injunctive relief.”
</p>

<p>
	 
</p>

<p>
	As for “tortious interference” and “defamation by implication,” the judge was similarly unimpressed.
</p>

<p>
	 
</p>

<p>
	“The fact that you might have a repeat customer who is dissuaded to buy your product due to a criticism of the product is not the type of business relationship the tortious interference with business relationship concept is intended to apply,” she said.
</p>

<p>
	 
</p>

<p>
	In the end, the judge said she would see the case through to its end, if that was really what everyone wanted, but “I will pray that you all come to a resolution of the case that doesn’t require all of this. This is a capitalist market and people say what they say. As long as it’s not false, they say what they say.”
</p>

<p>
	 
</p>

<p>
	She gave Proven until July 7 to amend its complaint if it wished.
</p>

<p>
	 
</p>

<p>
	On July 7, the company dismissed the lawsuit against McNally instead.
</p>

<p>
	 
</p>

<p>
	Proven also made a highly unusual request: Would the judge please seal almost the entire court record—including the request to seal?
</p>

<p>
	 
</p>

<p>
	Court records are presumptively public, but Proven complained about a “pattern of intimidation and harassment by individuals influenced by Defendant McNally’s content.” According to the company, a key witness had already backed out of the case, saying, “Is there a way to leave my name and my companies name out of this due to concerns of potential BLOW BACK from McNally or others like him?” Another witness, who did submit a declaration, wondered, “Is this going to be public? My concern is that there may be some backlash from the other side towards my company.”
</p>

<p>
	 
</p>

<p>
	McNally’s lawyer laid into this seal request, pointing out that the company had shown no concern over these issues until it lost its bid for a preliminary injunction. Indeed, “Proven boasted to its social media followers about how it sued McNally and about how confident it was that it would prevail. Proven even encouraged people to search for the lawsuit.” Now, however, the company “suddenly discover[ed] a need for secrecy.”
</p>

<p>
	 
</p>

<p>
	The judge has not yet ruled on the request to seal.
</p>

<h2>
	Another way
</h2>

<p>
	The strange thing about the whole situation is that Proven actually knew how to respond constructively to the first McNally video. Its own <a href="https://www.youtube.com/shorts/16nZqtT-1sI" rel="external nofollow">response video</a> opened with a bit of humor (the presenter drinks a can of Liquid Death), acknowledged the issue (“we’ve had a little bit of controversy in the last couple days”), and made clear that Proven could handle criticism (“we aren’t afraid of a little bit of feedback”).
</p>

<p>
	 
</p>

<p>
	The video went on to show how their locks work and provided some context on shimming attacks and their likelihood of real-world use. It ended by showing how users concerned about shimming attacks could choose more expensive but more secure lock cores that should resist the technique.
</p>

<p>
	 
</p>

<p>
	Quick, professional, non-defensive—a great way to handle controversy.
</p>

<p>
	 
</p>

<p>
	But it was all blown apart by the company’s angry social media statements, which were unprofessional and defensive, and the litigation, which was spectacularly ill-conceived as a matter of both law and policy. In the end, the case became a classic example of the <a href="https://en.wikipedia.org/wiki/Streisand_effect" rel="external nofollow">Streisand Effect</a>, in which the attempt to censor information can instead call attention to it.
</p>

<p>
	 
</p>

<p>
	Judging from the number of times the lawsuit talks about 1) ridicule and 2) harassment, it seems like the case quickly became a personal one for Proven’s owner and employees, who felt either mocked or threatened. That’s understandable, but being mocked is not illegal and should never have led to a lawsuit or a copyright claim. As for online harassment, it remains a serious and unresolved issue, but launching a personal vendetta—and on pretty flimsy legal grounds—against McNally himself was patently unwise. (Doubly so given that McNally had a huge following and had already responded to DMCA takedowns by creating further videos on the subject; this wasn’t someone who would simply be intimidated by a lawsuit.)
</p>

<p>
	 
</p>

<p>
	In the end, Proven’s lawsuit likely cost the company serious time and cash—and generated little but bad publicity.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/tech-policy/2025/10/suing-a-popular-youtuber-who-shimmed-a-130-lock-what-could-possibly-go-wrong/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 28 October 2025 at 3:38 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32092</guid><pubDate>Mon, 27 Oct 2025 17:39:34 +0000</pubDate></item><item><title>Your logins could be among 180M just added to Have I Been Pwned - how to check for free</title><link>https://nsaneforums.com/news/security-privacy-news/your-logins-could-be-among-180m-just-added-to-have-i-been-pwned-how-to-check-for-free-r32089/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>This is a free service that shows whether your online accounts have likely been 'pwned,' or compromised, in a data breach. </strong></span>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:18px;"><strong> ZDNET's key takeaways</strong></span>
</p>

<p>
	 
</p>

<ul>
	<li>
		    Two new Have I Been Pwned datasets added with millions of accounts.
	</li>
	<li>
		    Emails and passwords exposed in recent data breaches.
	</li>
	<li>
		    Check if your info was leaked and learn what to do next.
	</li>
</ul>

<p>
	 
</p>

<p>
	Cybersecurity expert Troy Hunt has added two new sets of compromised account records to the Have I Been Pwned database, including a massive dataset of 183 million accounts.
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>What is Have I Been Pwned?</strong></span>
</p>

<p>
	 
</p>

<p>
	Have I Been Pwned (HIBP) is a data breach "search engine" that allows anyone to submit their email address to see if any links to a data breach are publicly known.
</p>

<p>
	 
</p>

<p>
	HIBP is a free service that can give you an overview of whether or not it is likely your online accounts have been "pwned," or compromised, in a data breach. Once you've submitted your email address for review, you are told how many data breaches, if any, your information has been leaked in. A timeline will show when the data breach occurred, along with a useful summary of the stolen or dumped data.
</p>

<p>
	 
</p>

<p>
	You can also use the HIBP side service, Pwned Passwords, to see if a password you commonly use is linked to exposed datasets.
</p>

<p>
	 
</p>

<p>
	You can't use the service to view stolen or leaked data. Instead, HIBP gives you an overview of compromised data. At the time of writing, 917 breaches have been added to the service, which now brings its count to 15.32 billion accounts.
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>What information is included in these datasets?</strong></span>
</p>

<p>
	 
</p>

<p>
	According to the Have I Been Pwned updates, the first set includes 183 million records. Data was uploaded to HIBP on Oct. 21 with the assistance of Synthient, a threat intelligence service that shared the data with Hunt. In total, 183 million unique email addresses, the websites they were used on, and the passwords they were associated with were included.
</p>

<p>
	 
</p>

<p>
	The second addition is smaller at 3.9 million accounts. Added to HIBP on Oct. 27, this data breach relates to MyVidster, a video-sharing website that closed earlier this year and was reportedly used to bookmark and share pornography. Email addresses, usernames, and profile pictures were leaked on a public hacking forum.
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>Why does this dataset matter?</strong></span>
</p>

<p>
	 
</p>

<p>
	Synthient's contribution to HIBP is particularly interesting considering its sources. The data was aggregated while researcher Benjamin Brundage was exploring the stealer log ecosystem, in which website addresses, email addresses, and passwords are captured by information-stealing malware loaded onto victim devices.
</p>

<p>
	 
</p>

<p>
	After crawling sources including Telegram, social media websites, and forums, 3.5TB of information was collected -- or 23 billion rows of data.
</p>

<p>
	 
</p>

<p>
	It's often the case that these types of logs are reposted and recycled, and so Hunt worked with the researcher to check if any of the logs were already loaded into HIBP. In total, 92% of the dataset was preexisting, but this still left 183 million unique email addresses and 16.4 million previously unseen email addresses across both HIBP and infostealer logs. This highlights that just because data has been dumped online, it doesn't mean that it does not contain valid credentials that risk our online accounts.
</p>

<p>
	 
</p>

<p>
	Credential-stuffing lists were also in the Synthient dataset, which could be used in automated attacks against organizations. This dataset will be added in the near future once its accuracy is established.
</p>

<p>
	 
</p>

<p>
	"The truth is that, unlike a single data breach such as Ashley Madison, Dropbox, or the many other hundreds already in HIBP, stealer logs are more of a firehose of data that's just constantly spewing personal info all over the place," Hunt noted. "The data itself is still on point, but I'd like to see HIBP better reflect that firehose analogy and provide a constant stream of new data. Until then, Synthient's Threat Data will still sit in HIBP and be searchable in all the usual ways."
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>How do I know if I am involved in this collection?</strong></span>
</p>

<p>
	 
</p>

<p>
	The first step to take is to visit Have I Been Pwned and submit your email address. You will then be able to see what data breaches you are connected to, including Synthient's dataset.
</p>

<p>
	 
</p>

<p>
	If you find that your email address has been exposed, ensure you immediately change any password associated with it. You might also want to reduce your risk by deleting any online accounts you no longer use.
</p>

<p>
	 
</p>

<p>
	This latest update also brings home the lesson that you shouldn't reuse passwords across your online services. Of course, it is difficult to remember unique, complex passwords, but that's where a password manager can help you out. 
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.zdnet.com/article/your-logins-could-be-among-180m-just-added-to-have-i-been-pwned-how-to-check-for-free/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32089</guid><pubDate>Mon, 27 Oct 2025 15:57:40 +0000</pubDate></item><item><title>Gmail Passwords Confirmed As Part Of 183 Million Account Data Leak</title><link>https://nsaneforums.com/news/security-privacy-news/gmail-passwords-confirmed-as-part-of-183-million-account-data-leak-r32088/</link><description><![CDATA[<p>
	<em>Updated October 27 with an official statement from Google regarding the infostealer log dump and further advice from Gmail reagrding compromised passwords.</em>
</p>

<p>
	 
</p>

<p>
	Earlier this year, I reported on a data leak that included a whopping 184,162,718 passwords and logins impacting the likes of Apple, Facebook and Instagram users. That data leak was disclosed on May 22, and now, in a rather spooky seeming coincidence, news of 183 million passwords and login credentials from an April 2025 breach has emerged. Adding the details of website URLs, email addresses and passwords to the Have I Been Pwned database, owner Troy Hunt said the data consisted of both “stealer logs and credential stuffing lists” including confirmed Gmail login credentials. Here’s what we know and what you need to do.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:20px;"><strong>What We Know About The 183 Million Passwords Data Leak</strong></span>
</p>

<p>
	 
</p>

<p>
	Have I Been Pwned is something a staple resource for anyone who is genuinely concerned about their account login security. Why so? Because it’s the go-to for discovering when any of your email addresses, accounts, or passwords are found in data leaks, dark web password breach lists, and the like. Best of all, it’s entirely free to use. When a new entry appears with the number of affected accounts being 183 million, and the compromised data listed as email addresses and passwords, more than a few heads will pop up above the parapets and pay attention. Mine certainly did following the October 21 addition.
</p>

<p>
	 
</p>

<p>
	Having done some digging for further information, I was drawn to a lengthy analysis by Hunt himself, which looked inside the Synthient threat data provided to HIBP. Benjamin Brundage from Synthient revealed in a blog posting that the data came from the results of monitoring infostealer platforms across the course of close to a year. 
</p>

<p>
	 
</p>

<p>
	The total amount of information sent to HIBP comprised 3.5 terabytes of data, 23 billion rows of it in all. The output of the stealer logs concerned, Hunt said, consisted primarily of three things: website address, email address and password. “Someone logging into Gmail,” Hunt wrote, “ends up with their email address and password captured against gmail.com, hence the three parts.” Of course, there’s a lot of recycling of credentials that goes on in the cybercriminal world, so Hunt initially wanted to check the freshness of the database he had in his hands.
</p>

<p>
	 
</p>

<p>
	An analysis of a 94k sample revealed 92% were not, in fact, new. “Most of what has been seen before was in the ALIEN TXTBASE stealer logs,” Hunt confirmed. However, the math wizards out there will have noted that this steal leaves 8% that is new and fresh, or more than 14 million credentials if you extrapolate it. Actually, the final tally was 16.4 million previously unseen addresses in any data breach, not just stealer logs.
</p>

<p>
	 
</p>

<p>
	HIBP also checks to see if the credentials are genuine by sending out some of the details to people on the subscriber base who are impacted. “One of the respondents was already concerned there could be something wrong with his Gmail account,” Hunt said, and that person was able to validate that the entry was “an accurate password on my Gmail account.”
</p>

<p>
	 
</p>

<p>
	<span style="font-size:20px;"><strong>Check If Your Gmail Passwords Are Impacted Now</strong></span>
</p>

<p>
	 
</p>

<p>
	Of course, it is not just Gmail users who will be impacted by this leak, so I would advise everyone to go and check at HIBP to see if their account credentials might be included.
</p>

<p>
	 
</p>

<p>
	I reached out to my contacts at Google for a statement, and a spokesperson told me: “This report covers broad infostealer activity that targets many types of web activities. When it comes to email, users can help protect themselves by turning on 2-step verification and adopting passkeys as a simpler and stronger alternative to passwords."
</p>

<p>
	 
</p>

<p>
	Google also advised Gmail users that if they have any reason to believe that their account has been hacked, they should immediately sign in and review the account activity. If you can’t sign in, Google said, then head for the account recovery page and answer the questions that are presented to the best of your ability.
</p>

<p>
	 
</p>

<p>
	“Additionally, to help users, we have a process for resetting passwords when we come across large credential dumps such as this,” Google said.
</p>

<p>
	 
</p>

<p>
	You can check if your Gmail password is exposed, weak or used in for multiple account logins if you are a user of the Chrome password manager by using the Google password checkup feature. On a computer, this is accessible from Chrome by selecting Passwords and autofill from the top right menu, and then Google Password Manager|Checkup. 
</p>

<p>
	 
</p>

<p>
	This will reveal if you are using any passwords that are known to be compromised, as will most other password manager applications, as well as using the Have I Been Pwned? database check, as mentioned earlier, along with giving an indication of any weak passwords you may have in active use. “We’ll ask you to change your Google Account password if it might be unsafe, even if you don’t use Password Checkup,” Google said. And then, of course, there are those passwoirds that you reuse across multiple accounts and services, which Google will also inform you of. Talking of which, please do not do that, as it is a recipe for disaster, as this kind of password leak demonstrates all too well for Gmail users and everyone else, for that matter. As Google says, in a clear case of necessarily stating the obvious: "We recommend that you change any compromised passwords as soon as you can"
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.forbes.com/sites/daveywinder/2025/10/27/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32088</guid><pubDate>Mon, 27 Oct 2025 15:42:58 +0000</pubDate></item><item><title>Microsoft denies accusations of screenshotting your gameplay to train Gaming Copilot</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-denies-accusations-of-screenshotting-your-gameplay-to-train-gaming-copilot-r32078/</link><description><![CDATA[<p>
	Microsoft recently <a automate_uuid="8385621a-0448-4959-9066-24188772bb4a" href="https://www.neowin.net/news/microsoft-begins-rolling-out-gaming-copilot-for-game-bar-and-xbox-app-on-mobile/" rel="external nofollow">launched Gaming Copilot</a>, a new flavor of its AI efforts tailored to gamers so that they can get help and useful info on the go, right from the Game Bar on their PCs. However, not everyone is happy about it, and people are now accusing Microsoft of sneakily taking screenshots of their gameplay to train AI.
</p>

<p>
	 
</p>

<p>
	<a automate_uuid="b70dba66-fbd4-4b57-be05-d20a0a4d2684" href="https://www.resetera.com/threads/gaming-copilot-installing-automatically-on-windows-11-pcs-now-trains-microsofts-models-on-users-pc-gameplay.1332163/" rel="external nofollow">A post</a> on the ResetEra forum has a user complaining about Gaming Copilot sending screenshots of their gameplay to Microsoft (spotted by analyzing network activity) without consent. There is also a screenshot of privacy settings turned on to allow Microsoft to use data to train its models, which, allegedly, were enabled, again, without consent. Naturally, the post sparked outrage in replies, and Microsoft now has an answer to that. A Microsoft spokesperson said the following:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		When you’re actively using Gaming Copilot in Game Bar, it can use screenshots of your gameplay to get a better understanding of what’s happening in your game and provide you with more helpful responses. These screenshots are not used to train AI models, and Gaming Copilot is an optional feature that only has access to gameplay when you’re playing a game and actively using it.
	</p>

	<p>
		 
	</p>

	<p>
		Separately, Gaming Copilot may use its text or voice conversations with players to help train and improve AI. Players can adjust Gaming Copilot’s privacy settings by visiting ‘Settings’ in [the] Game Bar, followed by ‘Privacy Settings.
	</p>
</blockquote>

<p>
	In other words, Microsoft is not using screenshots of your gameplay to train AI. However, it still takes screenshots so that Copilot can understand what is going on. It is possible to let Microsoft use your conversations with Gaming Copilot to train models, but these features should be manually enabled in Gaming Copilot settings. <em>Neowin </em>checked Gaming Copilot on several machines, and all of them had training turned off by default.
</p>

<p>
	 
</p>

<p>
	Microsoft says that Gaming Copilot only takes screenshots when you are using the feature. Still, many users want to get rid of it, but the unfortunate reality is that the only way to remove Gaming Copilot is to get rid of Game Bar altogether, which, in turn, takes down quite a lot of actually useful features for PC gaming. What is clear is that despite Microsoft's efforts, people do not appear to be very happy with the overwhelming injection of AI into everyday products, particularly when it comes to privacy concerns.
</p>

<p>
	 
</p>

<p>
	Source: <a automate_uuid="8affa529-c0c7-4c18-94a8-be407baeacba" href="https://www.tomshardware.com/video-games/pc-gaming/microsoft-says-gaming-copilot-uses-screenshots-to-understand-in-game-events-not-for-training-ai-models-optional-feature-can-be-turned-off-but-not-easily-uninstalled" rel="external nofollow">Tom's Hardware</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-denies-accusations-of-screenshotting-your-gameplay-to-train-gaming-copilot/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 26 October 2025 at 4:49 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32078</guid><pubDate>Sat, 25 Oct 2025 18:50:26 +0000</pubDate></item><item><title>Mozilla: New Firefox extensions must disclose data collection practices</title><link>https://nsaneforums.com/news/security-privacy-news/mozilla-new-firefox-extensions-must-disclose-data-collection-practices-r32062/</link><description><![CDATA[<p>
	Starting next month, Mozilla will require Firefox extension developers to disclose whether their add-ons collect or share user data with third parties.
</p>

<p>
	 
</p>

<p>
	The devs will be required to disclose any new extension's data practices in the manifest.json file using a dedicated browser_specific_settings.gecko.data_collection_permissions key beginning November 3, 2025. Mozilla will also require all extension developers to adopt this framework in the first half of 2026.
</p>

<p>
	 
</p>

<p>
	Personally identifiable information that can be obtained through extension APIs or provided by the user <a href="https://extensionworkshop.com/documentation/develop/firefox-builtin-data-consent/#taxonomy" rel="external nofollow" target="_blank">includes</a>, but is not limited to, names, email addresses, search terms, and browsing activity data (e.g., domains, URLs, or categories of viewed pages).
</p>

<p>
	 
</p>

<p>
	Extensions that don't collect any personal data must also explicitly state this to ensure complete transparency for users about the data practices they can expect.
</p>

<p>
	 
</p>

<p>
	This information will appear during the installation prompt, along with any permissions requested. It will also be displayed on the extension's listing page on addons.mozilla.org and in the Permissions and Data section of Firefox's about:addons management page.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Firefox extensions data collection disclosure" class="ipsImage" height="250" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Firefox_extensions_data_collection_prompts.jpg">
		<figcaption>
			<em>Firefox extensions data collection disclosure (Mozilla)</em>
		</figcaption>
	</figure>
</div>

<p>
	"Developers can specify what data they wish to collect or transmit in their extensions manifest.json file. This information will be parsed by the browser and shown to the user when they first install the extension," <a href="https://blog.mozilla.org/addons/2025/10/23/data-collection-consent-changes-for-new-firefox-extensions/" rel="external nofollow" target="_blank">Mozilla explains</a>.
</p>

<p>
	 
</p>

<p>
	"A user can then choose to accept or reject the data collection, just like they do with extension permissions. The developer can also specify that the extension collects no data."
</p>

<p>
	 
</p>

<p>
	This requirement applies exclusively to newly submitted Firefox extensions. Existing add-ons won't need to comply until they update to use the new framework.
</p>

<p>
	 
</p>

<p>
	However, extensions that fail to properly declare their data collection practices will be blocked from submission to Mozilla's add-on repository, and their developers will receive explanatory error messages.
</p>

<p>
	 
</p>

<p>
	Last month, Mozilla also announced that it will allow Firefox extension devs to <a href="https://www.bleepingcomputer.com/news/software/mozilla-now-lets-firefox-add-on-devs-roll-back-bad-updates/" rel="external nofollow" target="_blank">roll back to previously approved versions</a> to address critical bugs and issues quickly.
</p>

<p>
	 
</p>

<p>
	In June, it <a href="https://www.bleepingcomputer.com/news/security/mozilla-launches-new-system-to-detect-firefox-crypto-drainer-add-ons/" rel="external nofollow" target="_blank">introduced a security feature</a> for its add-on portal designed to block malicious extensions that drain cryptocurrency wallets.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/software/mozilla-new-firefox-extensions-must-disclose-data-collection-practices/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 25 October 2025 at 4:32 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32062</guid><pubDate>Fri, 24 Oct 2025 18:33:04 +0000</pubDate></item><item><title>Report: Gaming Copilot AI is being trained by watching you play games, and it is on by default</title><link>https://nsaneforums.com/news/security-privacy-news/report-gaming-copilot-ai-is-being-trained-by-watching-you-play-games-and-it-is-on-by-default-r32061/</link><description><![CDATA[<p>
	Take this with a grain of salt, but users have reported another privacy transgression by Microsoft. According to the report by users from <a data-wpel-link="external" href="https://www.resetera.com/threads/gaming-copilot-installing-automatically-on-windows-11-pcs-now-trains-microsofts-models-on-users-pc-gameplay.1332163/" rel="external nofollow" target="_blank">the Resetera forum</a> and elsewhere, Copilot Gaming, an AI specially for gaming-related AI tasks, is taking screen captures of your gameplay for training.
</p>

<p>
	 
</p>

<p>
	While that would be fine if the user knew about it and enabled it willingly, it appears to be turned on automatically and without informing users about the data collecting and use of the data.
</p>

<p>
	 
</p>

<p>
	According to the user who noticed it first by monitoring network traffic, the AI is using OCR technology to identify text in the screenshots. If that reminds you of <a data-wpel-link="internal" href="https://www.ghacks.net/2024/09/30/windows-recall-microsofts-second-launch-attempt-after-devastating-criticism/" rel="external nofollow">Microsoft's Recall feature</a>, which it had to pull over similar privacy concerns and redo, you are not mistaken.
</p>

<p>
	 
</p>

<p>
	<strong>Note</strong>: Gaming Copilot is a beta feature. It is unclear if the recording happens in all regions or only in some. I checked on a recent Windows 11, version 24H2 system and did not have a Privacy settings section. However, the <a data-wpel-link="external" href="https://wccftech.com/microsoft-training-gaming-copilot-ai-watching-you-play-games-unless-you-turn-it-off/" rel="external nofollow" target="_blank">colleagues over at WCCFTech</a> checked and they had it and confirmed that it was enabled by default.
</p>

<h2>
	How to turn this off
</h2>

<figure aria-describedby="caption-attachment-210283" class="wp-caption alignnone" id="attachment_210283" style="width: 978px">
	<img alt="gaming-copilot-beta.png" class="ipsImage" decoding="async" height="720" width="720" src="https://www.ghacks.net/wp-content/uploads/2025/10/gaming-copilot-beta.png">
	<figcaption class="wp-caption-text" id="caption-attachment-210283">
		<p>
			The privacy settings of Gaming Copilot. 
		</p>

		<p>
			(screenshot by RedbullCola / Resetera)
		</p>
	</figcaption>
</figure>

<p>
	If you are a gamer on Windows 11, you may want to check if Gaming Copilot is being trained by monitoring what and how you play.
</p>

<p>
	 
</p>

<ol>
	<li>
		Open the Start menu.
	</li>
	<li>
		Type Game Bar and press the Enter-key. You may also use the shortcut Windows-G to get there directly.
	</li>
	<li>
		Select the Settings gear.
	</li>
	<li>
		Switch to Privacy settings.
	</li>
	<li>
		Toggle "Model training on text" to off.
	</li>
	<li>
		Go back.
	</li>
	<li>
		Open Capture settings.
	</li>
	<li>
		Toggle "Enable screenshots (experimental)".
	</li>
</ol>

<p>
	 
</p>

<p>
	It is probably a good idea to check if the setting exists, even if you do not play games on the Windows 11 system. Unless you really, really want to help Microsoft train its gaming AI, you might want to turn it off immediately.
</p>

<figure aria-describedby="caption-attachment-210285" class="wp-caption alignnone" id="attachment_210285" style="width: 975px">
	<img alt="copilot-screenshots.png" class="ipsImage" decoding="async" height="720" width="720" src="https://www.ghacks.net/wp-content/uploads/2025/10/copilot-screenshots.png">
	<figcaption class="wp-caption-text" id="caption-attachment-210285">
		<p>
			Gaming Copilot Capture settings 
		</p>

		<p>
			(Screenshot by RedbullCola / Resetera)
		</p>
	</figcaption>
</figure>

<p>
	The original thread starter posted another screenshot of another setting. Found under Capture settings, the preference "enable screenshots (experimental)" was enabled as well.
</p>

<p>
	 
</p>

<p>
	Microsoft did not display any onboarding or consent prompts to the user either, reportedly.
</p>

<p>
	 
</p>

<p>
	We asked Microsoft for comment, but have not heard back yet. We will update the article, if we get feedback from the company.
</p>

<p>
	 
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	<a href="https://www.ghacks.net/2025/10/24/report-gaming-copilot-ai-is-being-trained-by-watching-you-play-games-and-it-is-on-by-default/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 25 October 2025 at 4:30 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32061</guid><pubDate>Fri, 24 Oct 2025 18:31:49 +0000</pubDate></item><item><title>European Commission says Meta and TikTok could be violating DSA</title><link>https://nsaneforums.com/news/security-privacy-news/european-commission-says-meta-and-tiktok-could-be-violating-dsa-r32060/</link><description><![CDATA[<p>
	Preliminary findings released by the European Commission have found that Meta and TikTok have breached their obligations under the <a automate_uuid="11fc36fd-086c-4ed3-b925-e747a237d401" href="https://www.neowin.net/news/meta-must-stop-forcing-algorithmic-feeds-on-users-court-rules/" rel="external nofollow">Digital Services Act (DSA)</a>, which requires them to have measures in place against harmful and illegal content. There were two main breaches that the Commission flagged against Meta, while TikTok fell foul in one case.
</p>

<p>
	 
</p>

<p>
	For Meta and TikTok, the Commission said neither had given researchers adequate access to public data; it suggested that platforms may have put in place burdensome procedures and tools for researchers to request data access. Meta was also called out for not giving Facebook and Instagram users a user-friendly and easily accessible mechanism for flagging illegal content. The Commission said that Meta’s reporting process had unnecessary steps, additional demands, and used deceptive interface designs that can make the whole process more ineffective.
</p>

<p>
	 
</p>

<p>
	As expected, Meta has come out stating that it disagrees with the suggestion that it has breached the DSA. In a statement to Reuters, a Meta spokesperson said:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		“We have introduced changes to our content reporting options, appeals process, and data access tools since the DSA came into force and are confident that these solutions match what is required under the law in the EU.”
	</p>
</blockquote>

<p>
	Meanwhile, TikTok took a less definitive position, stating that it is reviewing the findings. As TikTok was flagged for not making it easy enough for researchers to access public data, it has been argued that easing data safeguards would put the DSA and the GDPR in direct tension and has urged regulators to provide more clarity on reconciling the issue.
</p>

<p>
	 
</p>

<p>
	The Commission has now given Meta and TikTok the chance to examine the situation and remedy the breaches. However, if the preliminary findings are confirmed, then the Commission could impose a fine of up to 6% of annual global sales.
</p>

<p>
	 
</p>

<p>
	Source: <a automate_uuid="b94bc39e-eafa-4b1d-8c9d-c37746d8f9b2" href="https://www.reuters.com/sustainability/boards-policy-regulation/eu-preliminarily-finds-meta-tiktok-breach-transparency-obligations-2025-10-24/" rel="external nofollow">Reuters</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/european-commission-says-meta-and-tiktok-could-be-violating-dsa/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 25 October 2025 at 4:30 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32060</guid><pubDate>Fri, 24 Oct 2025 18:30:31 +0000</pubDate></item><item><title>Windows disables File Explorer previews for dangerous file downloads</title><link>https://nsaneforums.com/news/security-privacy-news/windows-disables-file-explorer-previews-for-dangerous-file-downloads-r32056/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><em>To help plug up a hash leakage vulnerability, Windows is making it a little harder to peek at files you just grabbed from the web. </em></span>
</p>

<p>
	 
</p>

<p>
	If you’ve been using the internet for more than a month or so, you know that downloading files from unknown sites is a great way to get compromised. But the latest security update to Windows does a little extra to keep you safe. According to Microsoft, those who install the latest security updates will have previews in Explorer automatically disabled for downloaded files.
</p>

<p>
	 
</p>

<p>
	Why? According to the support page (spotted by Bleeping Computer), it’s because there’s a vulnerability with leaking hash. So thanks to Microsoft, your breakfast griddle will be notably tidier now that…oh, wait, no, it’s “a vulnerability where NTLM hash leakage might occur if users preview files containing HTML tags (such as &lt;link&gt;, &lt;src&gt;, and so forth) referencing external paths.” This could allegedly be used to capture “sensitive credentials.”
</p>

<p>
	 
</p>

<p>
	Mark of the Web metadata indicates that a file was downloaded from the internet, meaning Windows Defender will pay it a little extra attention. If you try to preview a downloaded file immediately, you’ll be met with the following alert message:
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	The file you are attempting to preview could harm your computer. If you trust the file and the source you received it from, open it to view its contents.
</p>

<p>
	 
</p>

<p>
	To disable this function after the October 14th, 2025 update, you’ll need to right-click the file, click “Properties,” then “Unblock.” It’ll need to be done for every file, and it might not take until you log into Windows again. 
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.pcworld.com/article/2952411/windows-disables-file-explorer-previews-for-dangerous-file-downloads.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32056</guid><pubDate>Fri, 24 Oct 2025 16:54:58 +0000</pubDate></item><item><title>Lying About Being in the Office? Microsoft Teams May Soon Rat You Out</title><link>https://nsaneforums.com/news/security-privacy-news/lying-about-being-in-the-office-microsoft-teams-may-soon-rat-you-out-r32055/</link><description><![CDATA[<p>
	Have you been avoiding your company's return-to-office edict? If you use Microsoft Teams, you may not be able to hide much longer, as a new feature will allow managers to see if their employees are in the office or not. 
</p>

<p>
	 
</p>

<p>
	The feature is currently under development and was spotted by TechRadar in the Microsoft 365 Roadmap. "When users connect to their organization's Wi-Fi, Teams will soon be able to automatically update their work location to reflect the building they're working from," Microsoft says. In other words, if they're not in the office, their managers could easily find out.
</p>

<p>
	 
</p>

<p>
	The feature should roll out in December on Windows and macOS. It will be disabled by default, but admins "will decide whether to enable it and require end-users to opt-in," Microsoft says. 
</p>

<p>
	 
</p>

<p>
	The report arrives as more companies are requiring employees to return to the office, either permanently or as part of a hybrid model (home/office). Microsoft itself has requested employees return to the office three days a week, if they live within 50 miles of a company office. 
</p>

<p>
	 
</p>

<p>
	In July, Teams got Slack-like threaded replies, which reduce clutter and let users keep all messages on one topic in a single thread. Last month, it also added Link Protection and File Protection features to warn users about potential malicious links and files appearing in chats. 
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.pcmag.com/news/lying-about-being-in-the-office-microsoft-teams-may-soon-rat-you-out" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32055</guid><pubDate>Fri, 24 Oct 2025 16:37:39 +0000</pubDate></item><item><title>Microsoft issues emergency Windows server security patch - update now or risk attack</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-issues-emergency-windows-server-security-patch-update-now-or-risk-attack-r32054/</link><description><![CDATA[<p>
	<span><em>Microsoft sounds the alarm after PoC emerges</em></span>
</p>

<p>
	 
</p>

<ul>
	<li>
		<strong>    Microsoft issues emergency patch for a critical WSUS flaw enabling remote code execution</strong>
	</li>
	<li>
		<strong>    CVE-2025-59287 allows unauthenticated attackers to gain SYSTEM privileges without user interaction</strong>
	</li>
	<li>
		<strong>    An out-of-band update was released after public exploit code surfaced online</strong>
	</li>
</ul>

<p>
	 
</p>

<p>
	Microsoft has issued an emergency Windows server security patch to fix a critical severity flaw apparently abused in the wild.
</p>

<p>
	 
</p>

<p>
	As part of its most recent Patch Tuesday cumulative update (October 14, 2025), Microsoft addressed CVE-2025-59287, a “deserialization of untrusted data” flaw found in Windows Server Update Service (WSUS).
</p>

<p>
	 
</p>

<p>
	WSUS allows IT admins to manage patching computers within their network. The flaw was given a severity score of 9.8/10 (critical), as it apparently allows for remote code execution (RCE) attacks. It can be abused in low-complexity attacks, without user interaction, granting unauthenticated, unprivileged threat actors the ability to run malicious code with SYSTEM privileges. In theory, it would allow them to pivot and infect other WSUS servers, too.
</p>

<p>
	 
</p>

<p>
	<span><strong>Mitigations and workarounds</strong></span>
</p>

<p>
	 
</p>

<p>
	Microsoft has now released an out-of-band (OOB) security update, after spotting publicly available proof-of-concept (PoC) code.
</p>

<p>
	 
</p>

<p>
	Although the Patch Tuesday update already included a fix for CVE-2025-59287, Microsoft issued an out-of-band update to urgently alert administrators and ensure immediate installation after the public exploit became available.
</p>

<p>
	 
</p>

<p>
	"If you haven't installed the October 2025 Windows security update yet, we recommend you apply this OOB update instead,” Microsoft explained in a security advisory. “After you install the update you will need to reboot your system."
</p>

<p>
	 
</p>

<p>
	There is also a way to mitigate the risk, Microsoft explained, saying that Windows servers without the WSUS server role enabled are not vulnerable. “If the WSUS server role is enabled, the server will become vulnerable if the fix is not installed before the WSUS server role is enabled," Microsoft explained.
</p>

<p>
	 
</p>

<p>
	Available workarounds include disabling the WSUS Server Role, or blocking all inbound traffic to ports 8530 and 8531 on the host firewall. In that case, though, Windows endpoints will stop receiving updates.
</p>

<p>
	 
</p>

<p>
	Microsoft also added WSUS will no longer show synchronization error details after installing the update, since the functionality was temporary in the first place.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.techradar.com/pro/security/microsoft-issues-emergency-windows-server-security-patch-update-now-or-risk-attack" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32054</guid><pubDate>Fri, 24 Oct 2025 16:31:08 +0000</pubDate></item><item><title>Researchers expose large-scale YouTube malware distribution network</title><link>https://nsaneforums.com/news/security-privacy-news/researchers-expose-large-scale-youtube-malware-distribution-network-r32052/</link><description><![CDATA[<p>
	Check Point researchers have uncovered, mapped and helped set back a stealthy, large-scale malware distribution operation on YouTube they dubbed the “YouTube Ghost Network.”
</p>

<p>
	 
</p>

<p>
	The network published more than 3,000 videos across compromised or fake channels, luring viewers with game cheats, cracked software, or pirated tools, but instead delivering malware or phishing pages.
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>The YouTube Ghost Network</strong></span>
</p>

<p>
	 
</p>

<p>
	The YouTube Ghost Network is strikingly similar to the Stargazers Ghost Network, a previously uncovered network of fake or hijacked GitHub accounts that served as a malware and phishing link Distribution-as-a-Service.
</p>

<p>
	 
</p>

<p>
	In the Stargazers Ghost Network, different accounts filled different roles. Some accounts directed targets to malicious downloads, others served malware, and others still starred, forked, and subscribed to malicious repositories, in an obvious attempt to make the other accounts appear legitimate to potential victims.
</p>

<p>
	 
</p>

<p>
	Similarly, the YouTube Ghost Network consists of video accounts, post accounts, and interact accounts.
</p>

<p>
	 
</p>

<p>
	Video accounts, which are either hijacked or created by the malware peddlers, upload videos that promise something appealing, e.g., a free/cracked version of Adobe Photoshop, or game hacks for popular games like Roblox. The descriptions contain download links or direct viewers to password-protected archives on services like Dropbox, Google Drive or MediaFire, and they often tell users to temporarily disable Windows Defender before installing the downloaded cracked software.
</p>

<p>
	 
</p>

<p>
	Post accounts publish community posts with the same links and passwords, and interact accounts flood comment sections with fake endorsements, creating a false sense of trust.
</p>

<p>
	 
</p>

<p>
	“While email phishing remains a well-known and persistent threat, our research reveals that adversaries are increasingly shifting toward more sophisticated, platform-based strategies, most notably, the deployment of Ghost Networks. These networks leverage the trust inherent in legitimate accounts and the engagement mechanisms of popular platforms to orchestrate large-scale, persistent, and highly effective malware campaigns,” the researchers noted.
</p>

<p>
	 
</p>

<p>
	“Targeting users through Ghost Networks is analogous to casting nets across the web, users must approach and essentially infect themselves.”
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>A resilient malware distribution network</strong></span>
</p>

<p>
	 
</p>

<p>
	The YouTube Ghost Network is designed to keep a low profile and to be resilient.
</p>

<p>
	 
</p>

<p>
	Most of the accounts are compromised legitimate YouTube channels. Once a channel is banned or flagged, the network simply replaces it, and because the roles are divided across different accounts, the operation remains resilient even when parts are taken down.
</p>

<p>
	 
</p>

<p>
	“Threat actors regularly updated links and payloads, enabling persistent infection chains even after partial removals,” the researchers noted.
</p>

<p>
	 
</p>

<p>
	“The technical sophistication of these campaigns is further evidenced by the use of password-protected archives, redundant hosting platforms, and frequent updates to both payloads and command-and-control (C2) infrastructure. These tactics are specifically designed to evade automated detection, reputation-based blocking, and manual review by both platform operators and security vendors.”
</p>

<p>
	 
</p>

<p>
	Most of the malware distributed through this network are infostealers, most notably the Lumma Stealer and Rhadamanthys.
</p>

<p>
	The network has been active since at least 2021, but in 2025, the number of malicious videos has tripled.
</p>

<p>
	 
</p>

<p>
	The YouTube Ghost Network has been crippled after the researchers flagged and Google took down over 3,000 malicious videos, but the individuals behind this effort are unlikely to give up easily.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.helpnetsecurity.com/2025/10/23/youtube-malware-distribution-network-ghost/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32052</guid><pubDate>Fri, 24 Oct 2025 11:16:35 +0000</pubDate></item><item><title>Microsoft shares Windows Server KB5070881 KB5070879 KB5070884 OOB updates for CVE-2025-59287</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-shares-windows-server-kb5070881-kb5070879-kb5070884-oob-updates-for-cve-2025-59287-r32051/</link><description><![CDATA[<p>
	Microsoft earlier today released emergency patches for a remote code execution security vulnerability on all supported Windows Server versions. Remote Code execution (RCE) attacks are a fairly dangerous cyberattack technique as threat actors do not require physical access to hardware to run malicious code intended to harm the victims.
</p>

<p>
	 
</p>

<p>
	The security flaw tracked under ID CVE-2025-59287 is affecting the Windows Server Update Services (WSUS) though Microsoft does not that servers that do not have the WSUS server role enabled are not vulnerable to this exploit. The emergency out-of-band (OOB) update, <a automate_uuid="faff3cd3-cece-4987-9473-6cfa30d378ad" href="https://www.neowin.net/news/microsoft-releases-kb5070762-windows-11-25h2-24h2-emergency-recovery-update/" rel="external nofollow">the second this month</a>, is now out and the company notes that this is cumulative in nature too just like other Windows updates, which means admins and users will not need to install any other previous update before installing this OOB update.
</p>

<p>
	 
</p>

<p>
	Microsoft writes: "An out-of-band (OOB) update was released today, October 23, 2025, to address this issue. This is a cumulative update, so you do not need to apply any previous updates before installing this update, as it supersedes all previous updates for affected versions. If you haven’t installed the October 2025 Windows security update yet, we recommend you apply this OOB update instead."
</p>

<p>
	 
</p>

<ul>
	<li>
		<p>
			Windows Server 2025 (KB5070881)
		</p>
	</li>
	<li>
		<p>
			Windows Server, version 23H2 (KB5070879)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2022 (KB5070884)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2019 (KB5070883)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2016 (KB5070882)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2012 R2 (KB5070886)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2012 (KB5070887)
		</p>

		<p>
			 
		</p>
	</li>
</ul>

<p>
	Micosoft notes that these updates are downloaded and installed automatically.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-shares-windows-server-kb5070881-kb5070879-kb5070884-oob-updates-for-cve-2025-59287/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 24 October 2025 at 6:11 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32051</guid><pubDate>Fri, 24 Oct 2025 08:12:26 +0000</pubDate></item></channel></rss>
