<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/18/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>US uncovers 100,000 SIM cards that could have &#x201C;shut down&#x201D; NYC cell network</title><link>https://nsaneforums.com/news/security-privacy-news/us-uncovers-100000-sim-cards-that-could-have-%E2%80%9Cshut-down%E2%80%9D-nyc-cell-network-r31480/</link><description><![CDATA[<h3>
	A "nation-state" is said to be involved.
</h3>

<p>
	The US Secret Service <a href="https://www.secretservice.gov/newsroom/releases/2025/09/us-secret-service-dismantles-imminent-telecommunications-threat-new-york" rel="external nofollow">announced this morning</a> that it has located and seized a cache of telecom devices large enough to "shut down the cellular network in New York City." And it believes a nation-state is responsible.
</p>

<p>
	 
</p>

<p>
	According to the agency, "more than 300 co-located SIM servers and 100,000 SIM cards" were discovered at multiple locations within the New York City area. Photos of the seized gear show what appear to be "SIM boxes" bristling with antennas and stuffed with SIM cards, then stacked on six-shelf racks. (SIM boxes are <a href="https://www.subex.com/blog/simbox-fraud-challenges-and-ai-powered-solutions-for-telecom-operators/" rel="external nofollow">often used for fraud</a>.) One photo even shows neatly stacked towers of punched-out SIM card packaging, suggesting that whoever assembled the system invested some quality time in just getting the whole thing set up.
</p>

<p>
	 
</p>

<p>
	The gear was identified as part of a Secret Service investigation into "anonymous telephonic threats" made against several high-ranking US government officials, but the setup seems designed for something larger than just making a few threats. The Secret Service believes that the system could have been capable of activities like "disabling cell phone towers, enabling denial of services attacks, and facilitating anonymous, encrypted communication between potential threat actors and criminal enterprises."
</p>

<p>
	 
</p>

<div class="ars-lightbox align-fullwidth my-5">
	<div class="ars-gallery-1-up my-5">
		<div class="ars-lightbox-item relative block h-full w-full overflow-hidden rounded-sm">
			<img alt="20250922_equipment_02-1024x1365.jpg" aria-labelledby="caption-2118532" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/09/20250922_equipment_02-1024x1365.jpg">
			<div class="pswp-caption-content" id="caption-2118532">
				<em>So many empty SIM card packages... </em>

				<div class="ars-gallery-caption-credit">
					<em><em>Secret Service </em></em>
				</div>

				<div class="ars-gallery-caption-credit">
					 
				</div>
				<em> </em>
			</div>
		</div>
	</div>

	<div class="flex flex-col flex-nowrap gap-5 py-5 md:flex-row">
		<div style="flex-basis: calc(50% - 10px);">
			<div class="ars-lightbox-item relative block h-full w-full overflow-hidden rounded-sm">
				<p>
					<img alt="SimBox.jpg" aria-labelledby="caption-2118536" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/09/SimBox.jpg">
				</p>

				<div class="pswp-caption-content" id="caption-2118536">
					<em>Close-up of a SIM box. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Secret Service </em></em>
					</div>
					<em> </em>
				</div>
			</div>

			<div class="md:hidden">
				 
			</div>
		</div>

		<div class="flex-1">
			<div class="ars-lightbox-item relative block h-full w-full overflow-hidden rounded-sm">
				<img alt="20250922_equipment_01-1024x1365.jpg" aria-labelledby="caption-2118531" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/09/20250922_equipment_01-1024x1365.jpg">
				<div class="pswp-caption-content" id="caption-2118531">
					<em>Just another random bedroom... stuffed with spy gear. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Secret Service </em></em>
					</div>
					<em> </em>
				</div>
			</div>

			<div class="md:hidden">
				 
			</div>
		</div>
	</div>

	<div class="ars-gallery-thumbnails grid grid-cols-4 gap-3 sm:grid-cols-6">
		<div class="aspect-square">
			<div class="ars-lightbox-item relative block h-full w-full overflow-hidden rounded-sm">
				<img alt="IMG_0766.jpeg" aria-labelledby="caption-2118537" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/09/IMG_0766.jpeg">
				<div class="pswp-caption-content" id="caption-2118537">
					<div class="ars-gallery-caption-credit">
						<em><em>Secret Service </em></em>
					</div>

					<div class="ars-gallery-caption-credit">
						 
					</div>
				</div>
			</div>
		</div>

		<div class="aspect-square">
			<div class="ars-lightbox-item relative block h-full w-full overflow-hidden rounded-sm">
				<img alt="SimBoxes.jpg" aria-labelledby="caption-2118535" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/09/SimBoxes.jpg">
				<div class="pswp-caption-content" id="caption-2118535">
					<div class="ars-gallery-caption-credit">
						<em><em>Secret Service </em></em>
					</div>
				</div>
			</div>
		</div>

		<div class="aspect-square">
			<div class="ars-lightbox-item relative block h-full w-full overflow-hidden rounded-sm">
				<img alt="20250922_equipment_03-1024x1365.jpg" aria-labelledby="caption-2118533" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/09/20250922_equipment_03-1024x1365.jpg">
				<div class="pswp-caption-content" id="caption-2118533">
					<div class="ars-gallery-caption-credit">
						<em><em>Secret Service </em></em>
					</div>

					<div class="ars-gallery-caption-credit">
						 
					</div>
				</div>
			</div>
		</div>
	</div>
</div>

<p>
	Analysis of data from so many devices will take time, but preliminary investigation already suggests that "nation-state threat actors" were involved; that is, this is probably some country's spy hardware. With the UN General Assembly taking place this week in New York, it is possible that the system was designed to spy on or disrupt delegates, but the gear was found in various places up to 35 miles from the UN. <a href="https://www.yahoo.com/news/articles/secret-disrupts-telecom-threat-near-134635567.html" rel="external nofollow">BBC reporting</a> suggests that the equipment was "seized from SIM farms at abandoned apartment buildings across more than five sites," and the ultimate goal remains unclear.
</p>

<p>
	 
</p>

<p>
	While the gear has been taken offline, no arrests have yet been made, and the investigation continues.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/09/us-uncovers-100000-sim-cards-that-could-have-shut-down-nyc-cell-network/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 24 September 2025 at 5:10 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31480</guid><pubDate>Tue, 23 Sep 2025 19:11:37 +0000</pubDate></item><item><title>Airport disruptions in Europe caused by a ransomware attack</title><link>https://nsaneforums.com/news/security-privacy-news/airport-disruptions-in-europe-caused-by-a-ransomware-attack-r31470/</link><description><![CDATA[<p>
	The disruptions over the weekend at several major European airports were caused by a ransomware attack targeting the check-in and boarding systems.
</p>

<p>
	 
</p>

<p>
	Among the airports suffering technical difficulties are Heathrow in London, Brussels Airport, and Brandenburg in Berlin. Cork and Dublin airports in Ireland also experienced difficulties, but the impact was minor.
</p>

<p>
	 
</p>

<p>
	The attack started on Friday night, according to Brussels Airport, and targeted “Collins Aerospace, the external provider of check-in and boarding systems.”
</p>

<p>
	 
</p>

<p>
	Hackers targeted the MUSE (Multi-User System Environment) system, which is used by multiple airlines to share check-in desks and boarding gate positions, as a solution to having their own dedicated infrastructure.
</p>

<p>
	 
</p>

<p>
	“Following a cyberattack on the American company Collins Aerospace, the external provider of check-in and boarding systems, there are disruptions to check-in operations at several European airports,” <a href="https://www.brusselsairport.be/en/passengers/infopage/difficult-airport-operations" rel="external nofollow" target="_blank">Brussels Airport says</a> on its website.
</p>

<h3>
	Ransomware attack confirmed
</h3>

<p>
	The European Union Agency for Cybersecurity (ENISA) <a href="https://www.theguardian.com/world/2025/sep/22/flight-delays-europe-cyber-attack-heathrow-brussels-berlin" rel="external nofollow" target="_blank">told The Guardian</a> in a statement on Monday that a ransomware attack caused the disruptions.
</p>

<p>
	 
</p>

<p>
	The incident impacted a significant number of flights, as more than 100were either delayed or cancelled, and thousands of passengers had to be processed manually.
</p>

<p>
	 
</p>

<p>
	Brussels Airport <a href="https://x.com/BrusselsAirport/status/1969760361650794828" rel="external nofollow" target="_blank">said</a> that disruptions continued on Monday and advised passengers to check the status of their flight before coming to the airport.
</p>

<p>
	 
</p>

<p>
	Collins Aerospace has been working to restore the system as soon as possible at impacted airports.
</p>

<p>
	 
</p>

<p>
	Law enforcement is also involved in the investigation, according to a spokesperson for the National Cyber Security Centre (NCSC) in the U.K.
</p>

<p>
	 
</p>

<p>
	“We are working with Collins Aerospace and affected UK airports, alongside Department for Transport and law enforcement colleagues, to fully understand the impact of an incident,” the <a href="https://www.ncsc.gov.uk/news/collins-aerospace-incident" rel="external nofollow" target="_blank">NCSC states</a>.
</p>

<p>
	 
</p>

<p>
	The agency is urging all organizations to turn to its free guidance, services, and tools to improve their security stance and reduce the risk of a cyberattack.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/airport-disruptions-in-europe-caused-by-a-ransomware-attack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 23 September 2025 at 12:30 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31470</guid><pubDate>Tue, 23 Sep 2025 02:31:08 +0000</pubDate></item><item><title>DOJ aims to break up Google&#x2019;s ad business as antitrust case resumes</title><link>https://nsaneforums.com/news/security-privacy-news/doj-aims-to-break-up-google%E2%80%99s-ad-business-as-antitrust-case-resumes-r31469/</link><description><![CDATA[<h3>
	The remedy phase of Google's adtech antitrust case begins.
</h3>

<p>
	Google is back in court, hoping to avoid a painful breakup of its advertising business. US District Judge Leonie Brinkema has already ruled that Google <a href="https://arstechnica.com/tech-policy/2025/04/google-loses-ad-tech-monopoly-trial-faces-additional-breakups/" rel="external nofollow">operated an illegal monopoly</a> in digital advertising, and now it's time to learn the consequences of that behavior. Google's had mixed luck with antitrust rulings lately, but it's not a great sign that Google has so many legal woes that it can be hard to keep them all straight.
</p>

<p>
	 
</p>

<p>
	The case that just got underway is the remedy phase of the AdTech trial, in which the DOJ secured a ruling against Google several months ago. The remedy phase of the search trial wrapped up recently, which ended with Google <a href="https://arstechnica.com/gadgets/2025/09/google-wont-have-to-sell-chrome-judge-rules/" rel="external nofollow">holding on to Chrome</a> but pledging an appeal to overturn the verdict. There's also the Google Play antitrust case, which was brought by Epic Games. In this case, Google has already lost its appeal, putting some major app changes on the table as it plans yet another appeal.
</p>

<p>
	 
</p>

<p>
	The Department of Justice (DOJ) and Google are squaring off in Virginia federal court for the next two weeks or so, and there are no surprises in opening arguments. The government says the only way to deal with a monopolist like this is to break it up, but Google says it has already made numerous changes, and there's no way to excise it from online advertising without breaking the market.
</p>

<p>
	 
</p>

<p>
	The AdTech remedy trial could mirror the search trial to a great degree. Indeed, the DOJ has pulled some language from that case, in which Judge Mehta opted not to force a divestment of Chrome. Mehta ruled that forcing a Chrome sale was a poor fit for the remedies as Chrome was not part of the illegal conduct.
</p>

<p>
	 
</p>

<p>
	However, government lawyers are hoping the AdTech case will turn out differently. The DOJ is asking the court to force Google to spin off Google Ad Manager (formerly Ad Exchange or AdX), the marketplace through which advertisers buy ads on Google's platform. The government was able to convince the court that Google's control of Ad Manager gave it an unfair advantage that boosted its own services, but is a breakup the proper remedy?
</p>

<p>
	 
</p>

<p>
	In its opening arguments in the AdTech case, the government claims Ad manager was intimately tied to the antitrust behavior, and its proposed remedies would pass muster under the standard Mehta employed. Government lawyers contend that remedies must be designed to restore competition, and Google's iron grip on online display ads can only be solved in one way. "Nothing short of a structural divestment is sufficient to bring meaningful change," said the DOJ's Julia Tarver Wood.
</p>

<h2>
	Google déjà vu
</h2>

<p>
	Google has come up with <a href="https://blog.google/outreach-initiatives/public-policy/doj-ad-tech-case-sept-2025" rel="external nofollow">its own proposal for remedies</a>, which is really just a formality. Google doesn't plan to accept any penalty and will appeal the case after the remedy phase. The company's proposal is just shy of nothing, suggesting it could make real-time bid amounts visible to everyone in auctions and end unified pricing rules to allow publishers to set different floors. Google also promises not to use "first look" and "last look" dynamics, which gave Google a major advantage in auctions. The company ended this practice several years ago, but it won't start again under the proposal.
</p>

<p>
	 
</p>

<p>
	Google is not exactly treading new ground with its arguments in this case—you could almost copy-paste "Chrome" in place of "Ad Manager" to get right back to Google's position in the search case. According to Google council Karen Dunn, the government's proposals are extreme and will cause "disruption and damage" to the advertising industry by shutting Google out. The company believes it has made enough changes of its own volition to resolve the issues cited in the case.
</p>

<p>
	 
</p>

<p>
	Google has also continued to draw on the AI explosion to reframe the case. Since the charges were filed in 2023, generative AI has become the primary focus at countless companies. In the search case, Google argued that AI was reshaping how people find information online, and therefore, structural remedies were unnecessary. Similarly, Google now says that AI ad tools like those developed by Meta and Perplexity show that digital advertising is still a vibrant market. Google's lawyers suggested that the DOJ is trying to rework an industry that has already been transformed.
</p>

<p>
	 
</p>

<p>
	It will be months before we learn what Brinkema has decided, but Google's headaches aren't over even if it comes out ahead in this case. The European Union is also going after the company's advertising business, recently issuing a <a href="https://arstechnica.com/gadgets/2025/09/europe-slaps-google-with-2-95b-euro-fine-over-advertising-monopoly/" rel="external nofollow">hefty fine</a>. Regulators say a breakup is on the table in Europe if Google doesn't come up with a proposal to address its market dominance.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2025/09/google-back-in-court-as-it-tries-to-avoid-advertising-business-breakup/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 23 September 2025 at 12:29 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31469</guid><pubDate>Tue, 23 Sep 2025 02:30:34 +0000</pubDate></item><item><title>Automaker giant Stellantis confirms data breach after Salesforce hack</title><link>https://nsaneforums.com/news/security-privacy-news/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack-r31468/</link><description><![CDATA[<p>
	Automotive manufacturing giant Stellantis has confirmed that attackers stole some of its North American customers' data after gaining access to a third-party service provider's platform.
</p>

<p>
	 
</p>

<p>
	Stellantis is a multinational corporation formed in 2021 after the merger of the PSA Group (Peugeot Société Anonyme) and Fiat Chrysler Automobiles (FCA). Stellantis is currently one of the largest automotive companies globally by revenue and the world's fifth-largest automaker by volume.
</p>

<p>
	 
</p>

<p>
	The company owns 14 major automotive brands, including Alfa Romeo, Chrysler, Citroën, Dodge, DS Automobiles, Fiat, Jeep, Lancia, Maserati, Opel, Peugeot, Ram, and Vauxhall, and it operates manufacturing facilities across Europe, North America, South America, and other regions, with operations in over 130 countries.
</p>

<p>
	 
</p>

<p>
	According to a statement published over the weekend, the attackers only stole customer contact information during the breach since the compromised platform was not used to store financial or other sensitive personal information.
</p>

<p>
	 
</p>

<p>
	"We recently detected unauthorized access to a third-party service provider's platform that supports our North American customer service operations," <a href="https://media.stellantisnorthamerica.com/newsrelease.do?id=27079&amp;mid=1" rel="external nofollow" target="_blank">Stellantis said</a>.
</p>

<p>
	 
</p>

<p>
	"Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation. We are also notifying the appropriate authorities and directly informing affected customers."
</p>

<p>
	 
</p>

<p>
	The auto giant also advised customers to be cautious of potential phishing attempts and to refrain from clicking suspicious links or sharing personal information when receiving unexpected emails, texts, or calls.
</p>

<p>
	 
</p>

<p>
	BleepingComputer reached out to Stellantis with questions about the incident, but a response was not immediately available.
</p>

<h2>
	Salesforce data breach claimed by ShinyHunters
</h2>

<p>
	Although Stellantis didn't share more information regarding this attack, BleepingComputer has learned that it is part of a <a href="https://www.bleepingcomputer.com/tag/salesforce/" rel="external nofollow" target="_blank">recent wave of Salesforce data breaches</a> linked with the ShinyHunters extortion group, which has affected numerous high-profile companies.
</p>

<p>
	 
</p>

<p>
	Earlier today, ShinyHunters claimed responsibility for the Stellantis data breach and told BleepingComputer that they had stolen over 18 million Salesforce records, including names and contact details, from the company's Salesforce instance.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-hackers-target-salesforce-accounts-in-data-extortion-attacks/" rel="external nofollow" target="_blank">Since the start of the year</a>, the extortion group has been <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/" rel="external nofollow" target="_blank">targeting Salesforce customers</a> in data theft attacks using voice phishing attacks, impacting companies such as <a href="http://ogle-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks/" rel="external nofollow" target="_blank">Google</a>, <a href="https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/" rel="external nofollow" target="_blank">Cisco</a>, <a href="https://www.bleepingcomputer.com/news/security/qantas-confirms-data-breach-impacts-57-million-customers/" rel="external nofollow" target="_blank">Qantas</a>, <a href="https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/" rel="external nofollow" target="_blank">Adidas</a>, <a href="https://www.bleepingcomputer.com/news/security/allianz-life-confirms-data-breach-impacts-majority-of-14-million-customers/" rel="external nofollow" target="_blank">Allianz Life</a>, <a href="https://www.bleepingcomputer.com/news/security/farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack/" rel="external nofollow" target="_blank">Farmers Insurance</a>, <a href="https://www.bleepingcomputer.com/news/security/hr-giant-workday-discloses-data-breach-amid-salesforce-attacks/" rel="external nofollow" target="_blank">Workday</a>, and LVMH subsidiaries, including <a href="https://www.bleepingcomputer.com/news/security/fashion-giant-dior-discloses-cyberattack-warns-of-data-breach/" rel="external nofollow" target="_blank">Dior</a>, <a href="https://www.bleepingcomputer.com/news/security/louis-vuitton-says-regional-data-breaches-tied-to-same-cyberattack/" rel="external nofollow" target="_blank">Louis Vuitton</a>, and <a href="https://www.chosun.com/english/industry-en/2025/05/26/ORM5MULB7NEM7EBUFVXHVLSB4A/" rel="external nofollow" target="_blank">Tiffany &amp; Co</a>.
</p>

<p>
	 
</p>

<p>
	ShinyHunters also claims they used <a href="https://www.bleepingcomputer.com/news/security/google-warns-salesloft-breach-impacted-some-workspace-accounts/" rel="external nofollow" target="_blank">stolen OAuth tokens</a> for Salesloft's Drift AI chat integration with Salesforce to steal sensitive information, such as passwords, AWS access keys, and Snowflake tokens, after gaining access to customers' Salesforce instances.
</p>

<p>
	 
</p>

<p>
	Using this method, they claimed to have stolen customer information from <a href="https://www.bleepingcomputer.com/news/security/google-warns-salesloft-breach-impacted-some-workspace-accounts/" rel="external nofollow" target="_blank">Google</a>, <a href="https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/" rel="external nofollow" target="_blank">Cloudflare</a>, <a href="https://www.bleepingcomputer.com/news/security/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise/" rel="external nofollow" target="_blank">Zscaler</a>, <a href="https://www.tenable.com/blog/tenable-response-to-salesforce-and-salesloft-drift-incident" rel="external nofollow" target="_blank">Tenable</a>, <a href="https://www.bleepingcomputer.com/news/security/palo-alto-networks-data-breach-exposes-customer-info-support-cases/" rel="external nofollow" target="_blank">Palo Alto Networks</a>, <a href="https://www.cyberark.com/resources/blog/salesloft-drift-incident-overview-and-cyberarks-response" rel="external nofollow" target="_blank">CyberArk</a>, <a href="https://www.nutanix.com/blog/third-party-salesloft-drift-application-incident-response-our-impact-and-action" rel="external nofollow" target="_blank">Nutanix</a>, <a href="https://blog.qualys.com/misc/2025/09/06/salesloft-drift-supply-chain-incident" rel="external nofollow" target="_blank">Qualys</a>, <a href="https://www.rubrik.com/blog/company/25/salesforce-connected-third-party-drift-application-supply-chain-incident-response" rel="external nofollow" target="_blank">Rubrik</a>, <a href="https://www.elastic.co/blog/elastic-update-salesloft-drift-security-incident" rel="external nofollow" target="_blank">Elastic</a>, <a href="https://www.beyondtrust.com/trust-center/security-advisories/salesforce-salesloft-drift-security-incident" rel="external nofollow" target="_blank">BeyondTrust</a>, <a href="https://www.proofpoint.com/us/blog/corporate-news/salesloft-drift-supply-chain-incident-response" rel="external nofollow" target="_blank">Proofpoint</a>, <a href="https://jfrog.com/help/r/salesforce-data-incident-identified-linked-to-third-party-salesloft-drift/salesforce-data-incident-identified-linked-to-third-party-salesloft-drift" rel="external nofollow" target="_blank">JFrog</a>, <a href="https://www.catonetworks.com/blog/cato-networks-statement-on-salesforce-salesloft-drift-incident/" rel="external nofollow" target="_blank">Cato Networks</a>, and <a href="https://www.driftbreach.com/" rel="external nofollow" target="_blank">many more</a>.
</p>

<p>
	 
</p>

<p>
	Last week, the <a href="https://www.bleepingcomputer.com/news/security/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/" rel="external nofollow" target="_blank">FBI released a Flash alert</a> sharing IOCs discovered during the attacks and warning about threat actors breaching organizations' Salesforce environments to steal data and extort victims. Meanwhile, the extortion group told BleepingComputer that <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/" rel="external nofollow" target="_blank">they had stolen over 1.5 billion Salesforce records</a> from 760 companies, using compromised Salesloft Drift OAuth tokens.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 23 September 2025 at 12:28 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31468</guid><pubDate>Tue, 23 Sep 2025 02:28:48 +0000</pubDate></item><item><title>Here&#x2019;s how potent Atomic credential stealer is finding its way onto Macs</title><link>https://nsaneforums.com/news/security-privacy-news/here%E2%80%99s-how-potent-atomic-credential-stealer-is-finding-its-way-onto-macs-r31467/</link><description><![CDATA[<h3>
	LastPass warns it's one of the latest to see its well-known brand impersonated.
</h3>

<p>
	Ads prominently displayed on search engines are impersonating a wide range of online services in a bid to infect Macs with a potent credential stealer, security companies have warned. The latest reported target is users of the LastPass password manager.
</p>

<p>
	 
</p>

<p>
	Late <a href="https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages" rel="external nofollow">last week</a>, LastPass said it detected a widespread campaign that used search engine optimization to display ads for LastPass macOS apps at the top of search results returned by search engines, including Google and Bing. The ads led to one of two fraudulent GitHub sites targeting LastPass, both of which have been taken down. The pages provided links promising to install LastPass on MacBooks. In fact, they installed a macOS credential stealer known as Atomic Stealer, or alternatively, Amos Stealer.
</p>

<h2>
	Dozens targeted
</h2>

<p>
	“We are writing this blog post to raise awareness of the campaign and protect our customers while we continue to actively pursue takedown and disruption efforts, and to also share indicators of compromise (IoCs) to help other security teams detect cyber threats,” LastPass said in the post.
</p>

<p>
	 
</p>

<p>
	LastPass is hardly alone in seeing its well-known brand exploited in such ads. The compromise indicators LastPass provided listed other software or services being impersonated as 1Password, Basecamp, Dropbox, Gemini, Hootsuite, Notion, Obsidian, Robinhood, Salesloft, SentinelOne, Shopify, Thunderbird, and TweetDeck. Typically, the ads offer the software in prominent fonts. When clicked, the ads lead to GitHub pages that install versions of Atomic that are disguised as the official software being falsely advertised.
</p>

<p>
	 
</p>

<p>
	The malicious installers sometimes offer to install the stealer through the downloading of a file in the Mac-proprietary .dmg format. After Apple added a detection to Gatekeeper—the malware protection built into macOS that blocks the installation of known malware—attackers started using a new method that bypassed it. This method masqueraded as a CAPTCHA, ostensibly to prove the user wasn’t a bot, by requiring the copying of a text string and pasting it into the Mac terminal window. In reality, the string was a command to download and install the malicious .dmg with no intervention from Gatekeeper. Researchers have warned of this Gatekeeper-bypassing technique for at least the <a href="https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/" rel="external nofollow">past 20 months</a>.
</p>

<p>
	 
</p>

<p>
	Despite attempts to raise awareness about Atomic, people have <a href="https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc" rel="external nofollow">continued to use it</a> widely, an indication that it remains effective. The post linked immediately above reports it being used against users of Homebrew, a tool that’s indispensable for many developers of macOS-compatible apps.
</p>

<p>
	 
</p>

<p>
	People should download software only from links provided on a site’s official webpage. In the event they view an ad and decide they want to install the app being promoted, they should open a new tab and visit the official website directly, rather than clicking on the download link in the ad. More information about Atomic is available <a href="https://www.crowdstrike.com/en-us/blog/falcon-prevents-cookie-spider-shamos-delivery-macos/" rel="external nofollow">here</a> and <a href="https://www.trendmicro.com/en_us/research/25/i/an-mdr-analysis-of-the-amos-stealer-campaign.html" rel="external nofollow">here</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 23 September 2025 at 12:25 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31467</guid><pubDate>Tue, 23 Sep 2025 02:26:40 +0000</pubDate></item><item><title>A jury will decide if Amazon illegally tricked people into paying for Prime</title><link>https://nsaneforums.com/news/security-privacy-news/a-jury-will-decide-if-amazon-illegally-tricked-people-into-paying-for-prime-r31450/</link><description><![CDATA[<h3>
	It’s the first of two major lawsuits it’s facing from the Federal Trade Commission.
</h3>

<p>
	Amazon is about to face a roughly month-long trial against the US Federal Trade Commission in Seattle to defend its Prime program from <a href="/2023/6/21/23768372/ftc-amazon-lawsuit-prime-dark-patterns-subscriptions" rel="">claims it tricked tens of millions of customers into signing up</a> for the membership and made it hard to quit.
</p>

<p>
	 
</p>

<p>
	It’s one of <a href="/policy/690440/e-barrett-prettyman-courthouse-dc-district-meta-google-antitrust-doge" rel="">several Big Tech trials</a> the US government has initiated that’s taking place this year, but the first major one in recent history against Amazon. Jury selection in the case will begin on Monday, which will be followed by opening arguments in the case. The FTC has separately sued Amazon for <a href="/2024/10/7/24264605/ftc-amazon-antitrust-motion-to-dismiss" rel="">allegedly anticompetitive practices</a> in a case that’s <a href="https://www.mlex.com/mlex/articles/2349550/us-ftc-amazon-antitrust-trial-rescheduled-to-february-2027" rel="external nofollow">set to begin in early 2027</a>.
</p>

<p>
	 
</p>

<p>
	The case beginning Monday alleges that Amazon deceived consumers about its sign-up and cancellation process for Prime benefits in violation of Section 5 of the FTC Act and the <a href="https://www.ftc.gov/legal-library/browse/statutes/restore-online-shoppers-confidence-act" rel="external nofollow">Restore Online Shoppers’ Confidence Act (ROSCA)</a>, which requires sellers to get consumers’ informed consent to charge them. The FTC alleges that Amazon used design tricks known as dark patterns to get users to sign up for Prime even when they might not have wanted to or without realizing what they were getting into. Once locked into a recurring subscription, the FTC alleges, Amazon made it difficult for users to cancel, and slow-rolled changes that would have made it easier for customers to do so, but cost Amazon revenue.
</p>

<p>
	 
</p>

<p>
	The government already won a significant ruling last week from Judge John Chun, who <a href="https://www.courthousenews.com/judge-deals-amazon-costly-defeat-ahead-of-ftc-trial/" rel="external nofollow">found on summary judgement</a> that Amazon violated ROSCA by collecting customers’ billing information before disclosing the material terms of the Prime membership. Chun also ruled that two Amazon executives could be held personally liable for violations if the FTC is able to prove them during the trial. Chun <a href="https://www.reuters.com/legal/government/us-judge-admonishes-amazon-over-disclosures-ftc-lawsuit-over-prime-service-2025-07-10/" rel="external nofollow">earlier admonished Amazon</a> for withholding documents from the FTC in a way that was “tantamount to bad faith.”
</p>

<p>
	 
</p>

<p>
	Amazon has denied it violated the law, with spokesperson Heather Layman calling the claims “false on the facts and the law” <a href="/2023/6/21/23768372/ftc-amazon-lawsuit-prime-dark-patterns-subscriptions" rel="">when it was filed in 2023</a>. “The truth is that customers love Prime, and by design we make it clear and simple for customers to both sign up for or cancel their Prime membership.” The company <a href="/2022/7/5/23195019/amazon-prime-cancellation-europe-european-union-dark-patterns" rel="">agreed to simplify its Prime cancellation process in Europe</a> in 2022 in response to pressure from regulators there.
</p>

<p>
	 
</p>

<p>
	Going after recurring subscription fees has been a popular tactic among both Republicans and Democrats. Lina Khan, who ran the FTC during the Biden administration, championed the click-to-cancel rule to make it as easy to cancel a membership as sign up, but it was<a href="/news/702398/ftc-click-to-cancel-rule-struck-down-appeals-court" rel=""> struck down by an appeals</a> court before taking effect. Current FTC Chair Andrew Ferguson opposed the rule as a commissioner, but the agency has continued the Amazon suit brought under Khan, and <a href="https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-takes-action-against-uber-deceptive-billing-cancellation-practices" rel="external nofollow">filed a new lawsuit against Uber</a> for allegedly making it difficult to cancel its Uber One food/grocery/rideshare discount subscription.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/policy/782197/amazon-prime-ftc-consumer-protection-trial" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Monday 22 September 2025 at 2:12 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31450</guid><pubDate>Sun, 21 Sep 2025 16:13:39 +0000</pubDate></item><item><title>Microsoft&#x2019;s Entra ID vulnerabilities could have been catastrophic</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft%E2%80%99s-entra-id-vulnerabilities-could-have-been-catastrophic-r31443/</link><description><![CDATA[<h3>
	They could've allowed attacker to gain access to virtually all Azure customer accounts.
</h3>

<p>
	As businesses around the world have shifted their digital infrastructure over the last decade from self-hosted servers to the <a href="https://www.wired.com/story/secret-hunting-bill-demirkapi/" rel="external nofollow">cloud</a>, they’ve benefitted from the standardized, built-in security features of major cloud providers like <a href="https://www.wired.com/story/microsoft-secure-future-initiative/" rel="external nofollow">Microsoft</a>. But with so much riding on these systems, there can be potentially <a href="https://www.wired.com/story/microsoft-cloud-attack-china-hackers/" rel="external nofollow">disastrous consequences</a> at a massive scale if something goes wrong. Case in point: Security researcher Dirk-jan Mollema recently stumbled upon a <a href="https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/" rel="external nofollow">pair of vulnerabilities</a> in Microsoft Azure’s identity and access management platform that could have been exploited for a potentially cataclysmic takeover of all Azure customer accounts.
</p>

<p>
	 
</p>

<p>
	Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and subscription management tools. Mollema has studied Entra ID security in depth and published multiple studies about weaknesses in the system, which was formerly known as Azure Active Directory. But while preparing to <a href="https://i.blackhat.com/BH-USA-25/Presentations/US-25-Mollema-Advanced-AD-to-Entra-ID-lateral-movement-techniques-Wednesday.pdf" rel="external nofollow">present</a> at the Black Hat security conference in Las Vegas in July, Mollema discovered two vulnerabilities that he realized could be used to gain global administrator privileges—essentially god mode—and compromise every Entra ID directory, or what is known as a “tenant.” Mollema says that this would have exposed nearly every Entra ID tenant in the world other than, perhaps, government cloud infrastructure.
</p>

<p>
	 
</p>

<p>
	“I was just staring at my screen. I was like, ‘No, this shouldn’t really happen,’” says Mollema, who runs the Dutch cybersecurity company Outsider Security and specializes in cloud security. “It was quite bad. As bad as it gets, I would say.”
</p>

<p>
	 
</p>

<p>
	“From my own tenants—my test tenant or even a trial tenant—you could request these tokens and you could impersonate basically anybody else in anybody else’s tenant,” Mollema adds. “That means you could modify other people's configuration, create new and admin users in that tenant, and do anything you would like.”
</p>

<p>
	 
</p>

<p>
	Given the seriousness of the vulnerability, Mollema disclosed his findings to the Microsoft Security Response Center on July 14, the same day that he discovered the flaws. Microsoft started investigating the findings that day and issued a fix globally on July 17. The company confirmed to Mollema that the issue was fixed by July 23 and implemented extra measures in August. Microsoft <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55241" rel="external nofollow">issued a CVE</a> for the vulnerability on September 4.
</p>

<p>
	 
</p>

<p>
	“We mitigated the newly identified issue quickly, and accelerated the remediation work underway to decommission this legacy protocol usage, as part of our Secure Future Initiative,” Tom Gallagher, Microsoft’s Security Response Center vice president of engineering, told WIRED in a statement. “We implemented a code change within the vulnerable validation logic, tested the fix, and applied it across our cloud ecosystem.”
</p>

<p>
	 
</p>

<p>
	Gallagher says that Microsoft found “no evidence of abuse” of the vulnerability during its investigation.
</p>

<p>
	 
</p>

<p>
	Both vulnerabilities relate to legacy systems still functioning within Entra ID. The first involves a type of Azure authentication token Mollema discovered known as Actor Tokens that are issued by an obscure Azure mechanism called the “Access Control Service.” Actor Tokens have some special system properties that Mollema realized could be useful to an attacker when combined with another vulnerability. The other bug was a major flaw in a historic Azure Active Directory application programming interface known as “Graph” that was used to facilitate access to data stored in Microsoft 365. Microsoft is in the process of retiring Azure Active Directory Graph and transitioning users to its successor, Microsoft Graph, which is designed for Entra ID. The flaw was related to a failure by Azure AD Graph to properly validate which Azure tenant was making an access request, which could be manipulated so the API would accept an Actor Token from a different tenant that should have been rejected.
</p>

<p>
	 
</p>

<p>
	“Microsoft built security controls around identity like conditional access and logs, but this internal impression token mechanism bypasses them all,” says Michael Bargury, the CTO at security firm Zenity. “This is the most impactful vulnerability you can find in an identity provider, effectively allowing full compromise of any tenant of any customer.”
</p>

<p>
	 
</p>

<p>
	If the vulnerability had been discovered by, or fallen into the hands of, malicious hackers, the fallout could have been devastating.
</p>

<p>
	 
</p>

<p>
	“We don't need to guess what the impact may have been; we saw two years ago what happened when Storm-0558 compromised a signing key that allowed them to log in as any user on any tenant,” Bargury says.
</p>

<p>
	 
</p>

<p>
	While the specific technical details are different, Microsoft revealed in July 2023 that the Chinese cyber espionage group known as Storm-0558 had stolen a cryptographic key that allowed them to generate authentication tokens and <a href="https://www.wired.com/story/microsoft-cloud-attack-china-hackers/" rel="external nofollow">access cloud-based Outlook email systems</a>, including those belonging to US government departments.
</p>

<p>
	 
</p>

<p>
	Conducted over the course of several months, a Microsoft postmortem on the Storm-0558 attack <a href="https://www.wired.com/story/china-backed-hackers-steal-microsofts-signing-key-post-mortem/" rel="external nofollow">revealed several errors</a> that led to the Chinese group slipping past cloud defenses. The security incident was one of a string of Microsoft issues around that time. These motivated the company to <a href="https://www.wired.com/story/microsoft-secure-future-initiative/" rel="external nofollow">launch its “Secure Future Initiative</a>,” which expanded protections for cloud security systems and set more aggressive goals for responding to vulnerability disclosures and issuing patches.
</p>

<p>
	 
</p>

<p>
	Mollema says that Microsoft was extremely responsive about his findings and seemed to grasp their urgency. But he emphasizes that his findings could have allowed malicious hackers to go even farther than they did in the 2023 incident.
</p>

<p>
	 
</p>

<p>
	“With the vulnerability, you could just add yourself as the highest privileged admin in the tenant, so then you have full access,” Mollema says. Any Microsoft service “that you use EntraID to sign into, whether that be Azure, whether that be SharePoint, whether that be Exchange—that could have been compromised with this.”
</p>

<p>
	 
</p>

<p>
	<em>This story originally appeared on <a href="https://www.wired.com/story/microsoft-entra-id-vulnerability-digital-catastrophe/" rel="external nofollow">wired.com</a>.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/09/microsofts-entra-id-vulnerabilities-could-have-been-catastrophic/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 21 September 2025 at 3:04 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31443</guid><pubDate>Sat, 20 Sep 2025 17:05:03 +0000</pubDate></item><item><title>Like it or not, your expensive Samsung smart fridge will soon show ads on the cover screen</title><link>https://nsaneforums.com/news/security-privacy-news/like-it-or-not-your-expensive-samsung-smart-fridge-will-soon-show-ads-on-the-cover-screen-r31411/</link><description><![CDATA[<p>
	Recently, a post by Reddit user u/angrycatmeowmeow went viral on the HomeAssistant subreddit, which had users speculating that Samsung is bringing ads to certain smart refrigerator models.
</p>

<p>
	 
</p>

<p>
	The <a automate_uuid="5af98a3b-f838-4daa-abe3-39086e50e5ae" href="https://old.reddit.com/r/homeassistant/comments/1nifp6c/they_finally_did_it_samsung_smart_fridge_one_of/" rel="external nofollow">post from angrycatmeowmeow</a> showed a photo of their Samsung smart refrigerator's cover screen, which was notifying them of an update. The on-screen text explained that after they update, they will be getting ads on the Cover screen for the Weather, Color, and Daily Board themes. The only way to avoid them, the notice stated, is to use the Art and Gallery themes, which will continue to be ad-free.
</p>

<p>
	 
</p>

<div class="img-center">
	<figure class="image image--expandable">
		<img alt="Ad notice on Samsung Fridge" class="ipsImage" height="720" width="708" src="https://cdn.neowin.com/news/images/uploaded/2025/09/1758210844_foh1lyeypipf1.webp">
		<figcaption>
			<em>Image via <a automate_uuid="9ceda1a4-1098-4c44-81bf-ab51cc69289f" href="https://old.reddit.com/r/homeassistant/comments/1nifp6c/they_finally_did_it_samsung_smart_fridge_one_of/" rel="external nofollow">u/angrycatmeowmeow</a></em>
		</figcaption>
	</figure>
</div>

<p>
	When Android Authority <a automate_uuid="e48d85ff-16e1-4ffd-9a75-e0dd62bcb777" href="https://www.androidauthority.com/samsung-confirms-smart-refrigerator-ads-are-coming-3598848/" rel="external nofollow">reached out to Samsung</a> for clarification on the matter, the company responded that it is "committed to innovation and enhancing everyday value" and confirmed that the ads are part of a "pilot program" for certain Family Hub refrigerators in the United States. Ads will appear only when the screen is idle.
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Samsung is committed to innovation and enhancing every day value for our home appliance customers. As part of our ongoing efforts to strengthen that value, we are conducting a pilot program to offer promotions and curated advertisements on certain Samsung Family Hub refrigerator models in the U.S. market.
	</p>
</blockquote>

<p>
	If you are not familiar, the <a automate_uuid="760ce76e-962b-4fbc-a455-3451bea1b143" href="https://www.samsung.com/us/explore/family-hub-refrigerator/overview/" rel="external nofollow">Samsung Family Hub lineup</a> is a series of premium refrigerators that feature massive touchscreens. These displays can go up to 32 inches on some models. The fridges have features like AI Vision, which recognizes what is inside your appliance. You can also view the contents from anywhere with your smartphone, so you know when you are out of milk. These are expensive machines that can cost well over $3,000.
</p>

<p>
	 
</p>

<p>
	The good news is that Samsung promises that a dismissed ad will not appear again. Of course, this does not mean new ads will not take their place.
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		The Cover Screen appears when a Family Hub screen is idle. Ad design format may change depending on Family Hub personalization options for the Cover Screen, and advertising will not appear when Cover Screen displays Art Mode or picture albums. Advertisements can be dismissed on the Cover Screens where ads are shown, meaning that specific ads will not appear again during the campaign period.
	</p>
</blockquote>

<p>
	The company did not say whether this program will expand to other regions or models. So, it is quite possible for this "feature" to become standard across more of its expensive smart appliances down the line.
</p>

<p>
	 
</p>

<p>
	If you are affected by this and want to get rid of the ads, <a automate_uuid="9d8ee169-800e-4a66-88fe-78591085ac89" href="https://old.reddit.com/r/homeassistant/comments/1nifp6c/they_finally_did_it_samsung_smart_fridge_one_of/neisb0g/" rel="external nofollow">one user suggested</a> that you could wildcard block <code>samsungiotcloud.com</code> on your network. This may stop the fridge from communicating with the servers that deliver the ads. If that works for you, there is a significant catch: angrycatmeowmeow confirmed that blocking that domain seems to break the internal camera.
</p>

<p>
	 
</p>

<p>
	Speaking of ad blocking, Google <a automate_uuid="9af2348a-4d5c-47ba-940e-c4c55fb13442" href="https://www.neowin.net/news/google-lists-a-reason-explaining-why-ad-blockers-on-youtube-are-a-bad-thing/" rel="external nofollow">recently provided</a> a new reason to discourage users from blocking ads on YouTube, claiming that ad blockers interfere with view counts. The company suggests that channels may see their traffic metrics fluctuate if a large portion of their audience uses these tools.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/like-it-or-not-your-expensive-samsung-smart-fridge-will-soon-show-ads-on-the-cover-screen/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 19 September 2025 at 4:42 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31411</guid><pubDate>Thu, 18 Sep 2025 18:46:05 +0000</pubDate></item><item><title>Google lists a reason explaining why ad blockers on YouTube are a bad thing</title><link>https://nsaneforums.com/news/security-privacy-news/google-lists-a-reason-explaining-why-ad-blockers-on-youtube-are-a-bad-thing-r31410/</link><description><![CDATA[<p>
	If you have been reading Neowin then you are probably familiar with Google's stance on content blockers like ad blockers on YouTube. For those that may be wondering, the company is definitely not a fan of it as it has been trying to make life harder for users who use such apps and services to block out ads.
</p>

<p>
	 
</p>

<p>
	For example, earlier this year, <a automate_uuid="56aca9b1-f753-4e63-b108-6a8c647cbb22" href="https://www.neowin.net/news/google-not-letting-youtube-videos-play-with-opera-firefox-adblockers-chrome-is-slow/" rel="external nofollow">Neowin noticed how having an ad blocker on</a> meant that certain affected users were not able to proceed with playing the videos they were trying to watch. And last year in 2024, it was reported that Google was testing <a automate_uuid="cfe5f102-06f9-4b3b-bd74-9ec0c3e8156c" href="https://www.neowin.net/news/google-wants-to-make-it-impossible-to-block-youtube-ads-as-they-may-be-inside-videos/" rel="external nofollow">unblockable server-side ads</a> on the video platform. Later that same year, the tech giant was also accused of shenanigans regarding the<a automate_uuid="65b00b3d-3139-413f-919e-5d89e4298487" href="https://www.neowin.net/news/after-users-accusation-youtube-comes-out-clean-regarding-hiding-the-ad-skip-button/" rel="external nofollow"> "skip ad" button</a>.
</p>

<p>
	 
</p>

<p>
	To be fair to Google, there have been instances where bugs in ad-blocking scripts have <a automate_uuid="c3e335d3-90ec-43f5-b350-9eee1fc6009e" href="https://www.neowin.net/news/adblock-google-did-not-slow-down-and-lag-youtube-performance-with-ad-blocker-on/" rel="external nofollow">led to issues on YouTube</a>. And according to a new support article published by it this week, it looks like ad blockers are also impacting the YouTube view counter as Google has blamed content blockers, among other things, as the culprit behind the reduced hits on various videos from different creators.
</p>

<p>
	 
</p>

<p>
	The company says the ad blockers make view count metrics inaccurate thus leading to bigger fluctuations in the traffic. It <a automate_uuid="748d66d2-acba-4cb2-8263-9ed936c36597" href="https://support.google.com/youtube/thread/373195597" rel="external nofollow">writes</a><span>:</span>
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		<strong>Viewers Using Ad Blockers &amp; Other Content Blocking Tools</strong>: Ad blockers and other extensions can impact the accuracy of reported view counts. Channels whose audiences include a higher proportion of users utilizing such tools may see more fluctuations in traffic related to updates to these tools.
	</p>
</blockquote>

<p>
	With this message, Google likely hopes that creators themselves will begin to encourage their viewers to disable content blockers.
</p>

<p>
	 
</p>

<p>
	While the reason cited by Google for reduced hits is certainly plausible, it is also noteworthy that with the rise of AI chatbots and AI scrapers, people may simply not be watching a video to get the information they wish to have.
</p>

<p>
	 
</p>

<p>
	AI summaries are getting popular and Neowin too has seen greatly reduced human traffic over the last year or so since AI search began to be more relevant and popular. Google however <a automate_uuid="85a9d9bb-b3df-47cd-b227-730815dd7f07" href="https://blog.google/products/search/ai-search-driving-more-queries-higher-quality-clicks/" rel="external nofollow">claims the opposite</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/google-lists-a-reason-explaining-why-ad-blockers-on-youtube-are-a-bad-thing/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 19 September 2025 at 4:35 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31410</guid><pubDate>Thu, 18 Sep 2025 18:36:54 +0000</pubDate></item><item><title>Google patches sixth Chrome zero-day exploited in attacks this year</title><link>https://nsaneforums.com/news/security-privacy-news/google-patches-sixth-chrome-zero-day-exploited-in-attacks-this-year-r31409/</link><description><![CDATA[<p>
	Google has released emergency security updates to patch a Chrome zero-day vulnerability, the sixth one tagged as exploited in attacks since the start of the year.
</p>

<p>
	 
</p>

<p>
	While it didn't specifically say whether this security flaw is still being actively abused in the wild, the company warned that it has a public exploit, a common indicator of active exploitation.
</p>

<p>
	 
</p>

<p>
	"Google is aware that an exploit for CVE-2025-10585 exists in the wild," <a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html" rel="external nofollow" target="_blank">Google warned</a> in a security advisory published on Wednesday.
</p>

<p>
	 
</p>

<p>
	This high-severity zero-day vulnerability is caused by a <a href="https://cwe.mitre.org/data/definitions/843.html" rel="external nofollow" target="_blank">type confusion</a> weakness in the web browser's V8 JavaScript engine, reported by Google's Threat Analysis Group on Tuesday.
</p>

<p>
	 
</p>

<p>
	Google TAG frequently flags zero-days exploited by government-sponsored threat actors in targeted spyware campaigns targeting high-risk individuals, including but not limited to opposition politicians, dissidents, and journalists.
</p>

<p>
	 
</p>

<p>
	The company mitigated the security issue one day later with the release of 140.0.7339.185/.186 for Windows/Mac, and 140.0.7339.185 for Linux, versions that will roll out to the Stable Desktop channel over the coming weeks.
</p>

<p>
	 
</p>

<p>
	While Chrome automatically updates when new security patches are available, you can speed up the process by going to the Chrome menu &gt; Help &gt; About Google Chrome, allowing the update to finish, and then clicking the 'Relaunch' button to install it immediately.
</p>

<p>
	 
</p>

<p>
	<img alt="Chrome 140.0.7339.186" class="ipsImage" height="239" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Chrome%20140_0_7339_186.png">
</p>

<p>
	 
</p>

<p>
	Although Google has already confirmed that CVE-2025-10585 was used in attacks, it still has to share additional details regarding in-the-wild exploitation.
</p>

<p>
	 
</p>

<p>
	"Access to bug details and links may be kept restricted until a majority of users are updated with a fix," Google said. "We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed."
</p>

<p>
	 
</p>

<p>
	This is the sixth actively exploited Chrome zero-day fixed by Google this year, with five more patched in March, May, June, and July.
</p>

<p>
	 
</p>

<p>
	In July, it addressed another actively exploited zero-day (<a href="https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-sandbox-escape-zero-day-in-chrome/" rel="external nofollow" target="_blank">CVE-2025-6558)</a> reported by Google TAG researchers, which allowed attackers to escape the browser's sandbox protection.
</p>

<p>
	 
</p>

<p>
	Google released additional emergency security updates in May to address a Chrome zero-day (<a href="https://www.bleepingcomputer.com/news/security/google-fixes-high-severity-chrome-flaw-with-public-exploit/" rel="external nofollow" target="_blank">CVE-2025-4664</a>) that let attackers hijack accounts, and fixed an out-of-bounds read and write weakness (<a href="https://www.bleepingcomputer.com/news/security/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/" rel="external nofollow" target="_blank">CVE-2025-5419</a>) in Chrome's V8 JavaScript engine discovered by Google TAG in June.
</p>

<p>
	 
</p>

<p>
	In March, it also patched a high-severity sandbox escape flaw (<a href="https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/" rel="external nofollow" target="_blank">CVE-2025-2783</a>) reported by Kaspersky, which was used in espionage attacks against Russian government organizations and media outlets.
</p>

<p>
	 
</p>

<p>
	Last year, <a href="https://www.bleepingcomputer.com/news/security/google-tags-a-tenth-chrome-zero-day-as-exploited-this-year/" rel="external nofollow" target="_blank">Google patched 10 more zero-day bugs</a> that were either demoed during Pwn2Own hacking competitions or exploited in attacks.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-patches-sixth-chrome-zero-day-exploited-in-attacks-this-year/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>
<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedauthorid="56074" data-embedcontent="" data-embedid="embed6045501938" src="https://nsaneforums.com/topic/476172-google-chrome-14007339186/?do=embed&amp;comment=1877655&amp;embedComment=1877655&amp;embedDo=findComment#comment-1877655" style="overflow: hidden; height: 334px; max-width: 502px;"></iframe>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 19 September 2025 at 4:33 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31409</guid><pubDate>Thu, 18 Sep 2025 18:34:57 +0000</pubDate></item><item><title>Amazon is creating more tools to fill its site with AI ads</title><link>https://nsaneforums.com/news/security-privacy-news/amazon-is-creating-more-tools-to-fill-its-site-with-ai-ads-r31388/</link><description><![CDATA[<h3>
	Sellers can now interact with an AI chatbot to generate ads that match their branding.
</h3>

<p>
	Amazon is opening the door to even more AI ads by offering sellers access to a new chatbot that can generate promos with a simple text prompt. <a href="https://advertising.amazon.com/library/news/amazon-ads-agentic-ai-creative-tool" rel="external nofollow">With the new tool</a>, Amazon sellers can describe the type of ad they’d like to see, and the AI chatbot will draw from a seller’s brand guidelines, product pages, and other store details to generate a concept, whether it’s for a static advertisement or a video ad.
</p>

<p>
	 
</p>

<p>
	An example shared by Amazon shows how sellers can go from asking the AI chatbot to create taglines and images for a product, to having it write a script, add music, generate a voiceover, and lay out a storyboard. “This tool reduces the time and cost of designing creative ads, encouraging advertisers to explore and experiment rapidly,” Amazon writes. The ads can appear on Amazon’s online marketplace and across its other properties like Prime Video, the Kindle, and even Twitch.
</p>

<p>
	 
</p>

<div>
	<div class="_1ymtmqpj">
		<div>
			<div class="duet--media--content-warning ucljxw0">
				<div class="duet--article--image-gallery-image kqz8fh0" id="dmcyOmltYWdlOjc4MDA1MQ==">
					<a class="kqz8fh1" data-pswp-height="2268" data-pswp-width="4031" href="https://platform.theverge.com/wp-content/uploads/sites/2/2025/09/amazon-ai-storyboard.jpg?quality=90&amp;strip=all&amp;crop=0,0,100,100" rel="external nofollow" target="_blank"><img alt="Amazon’s AI chatbot can generate a storyboard and more." class="ipsImage" data-chromatic="ignore" data-nimg="fill" decoding="async" height="720" width="720" src="https://platform.theverge.com/wp-content/uploads/sites/2/2025/09/amazon-ai-storyboard.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1080"></a>
				</div>
			</div>
		</div>

		<div class="duet--media--caption qama0i0">
			<div>
				<em>Amazon’s AI chatbot can generate a storyboard and more.</em>
			</div>

			<p>
				<cite class="duet--article--dangerously-set-cms-markup _1xwtict2 qama0i1">Image: Amazon</cite>
			</p>

			<p>
				 
			</p>
		</div>
	</div>
</div>

<p>
	The tool is similar to the <a href="https://ads.tiktok.com/help/article/about-symphony-creative-studio?lang=en" rel="external nofollow">AI chatbot-style interface</a> that advertisers on TikTok can use <a href="https://www.reuters.com/technology/artificial-intelligence/tiktok-launches-ai-powered-video-platform-advertisers-globally-2024-11-14/" rel="external nofollow">to generate video ads</a>.. It also builds on Amazon’s existing AI tools, which already let sellers <a href="/news/685160/amazon-ads-ai-video-generator-us-launch-availability" rel="">generate AI videos showcasing</a> their products. Amazon says its AI chatbot is still in beta and runs <a href="/2024/12/3/24312260/amazon-nova-foundation-ai-models-anthropic" rel="">Amazon’s Nova AI model</a>, as well as Anthropic’s Claude.
</p>

<p>
	 
</p>

<p>
	Amazon is <a href="https://www.aboutamazon.com/news/innovation-at-amazon/seller-assistant-agentic-ai" rel="external nofollow">adding new “agentic” capabilities</a> to its AI-powered seller assistant as well, allowing it to monitor inventory levels and provide information about how a seller can “optimize” their business by flagging items that are slow to sell or suggesting price changes. The seller assistant can now scan a seller’s account for product listings that may violate new product safety policies, too, in addition to suggesting new types of products to sell based on customer behavior.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/news/780045/amazon-ai-ads-chatbot-inventory-monitoring" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 18 September 2025 at 4:34 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31388</guid><pubDate>Wed, 17 Sep 2025 18:35:14 +0000</pubDate></item><item><title>Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service-r31387/</link><description><![CDATA[<p>
	Microsoft and Cloudflare have disrupted a massive Phishing-as-a-Service (PhaaS) operation, known as RaccoonO365, that helped cybercriminals steal thousands of Microsoft 365 credentials.
</p>

<p>
	 
</p>

<p>
	In early September 2025, in coordination with <a href="https://www.cloudflare.com/threat-intelligence/research/report/cloudflare-participates-in-global-operation-to-disrupt-raccoono365/" rel="external nofollow" target="_blank">Cloudflare's Cloudforce One</a> and Trust and Safety teams, Microsoft's Digital Crimes Unit (DCU) disrupted the cybercrime operation by seizing 338 websites and Worker accounts linked to RaccoonO365.
</p>

<p>
	 
</p>

<p>
	The cybercrime group behind this service (also tracked by Microsoft as Storm-2246) has stolen at least 5,000 Microsoft credentials from 94 countries since at least July 2024, using RaccoonO365 phishing kits that bundled CAPTCHA pages and anti-bot techniques to appear legitimate and evade analysis.
</p>

<p>
	 
</p>

<p>
	For instance, a large-scale RaccoonO365 tax-themed phishing campaign targeted over 2,300 organizations in the United States in April 2025, but these phishing kits have also been deployed in attacks against more than 20 U.S. healthcare organizations.
</p>

<p>
	 
</p>

<p>
	The credentials, cookies, and other data stolen from victims' OneDrive, SharePoint, and email accounts were later employed in financial fraud attempts, extortion attacks, or as initial access to other victims' systems.
</p>

<p>
	 
</p>

<p>
	"This puts public safety at risk, as RaccoonO365 phishing emails are often a precursor to malware and ransomware, which have severe consequences for hospitals," <a href="https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/" rel="external nofollow" target="_blank">said Steven Masada</a>, Assistant General Counsel for Microsoft's Digital Crimes Unit.
</p>

<p>
	 
</p>

<p>
	"In these attacks, patient services are delayed, critical care is postponed or canceled, lab results are compromised, and sensitive data is breached, causing major financial losses and directly impacting patients."
</p>

<p>
	 
</p>

<p>
	RaccoonO365 has been renting subscription-based phishing kits through a private Telegram channel, which had over 840 members as of August 25, 2025. The prices ranged from $355 for a 30-day plan to $999 for a 90-day subscription, all paid in USDT (TRC20, BEP20, Polygon) or Bitcoin (BTC) cryptocurrency.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="RaccoonO365 Telegram channel" class="ipsImage" height="454" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/RaccoonO365-Telegram-channel.jpg">
		<figcaption>
			<em>RaccoonO365 Telegram channel (Cloudflare)</em>
		</figcaption>
	</figure>
</div>

<p>
	Microsoft estimated that the group has received at least $100,000 in cryptocurrency payments so far, suggesting there are approximately 100 to 200 subscriptions; however, the actual number of subscriptions sold is likely much higher.
</p>

<p>
	 
</p>

<p>
	During its investigation, the Microsoft DCU also found that the leader of RaccoonO365 is Joshua Ogundipe, who lives in Nigeria.
</p>

<p>
	 
</p>

<p>
	Cloudflare also believes that RaccoonO365 also collaborates with Russian-speaking cybercriminals, given the use of Russian in its Telegram bot's name.
</p>

<p>
	 
</p>

<p>
	"Based on Microsoft's analysis, Ogundipe has a background in computer programming and is believed to have authored the majority of the code," Masada added.
</p>

<p>
	 
</p>

<p>
	"An operational security lapse by the threat actors in which they inadvertently revealed a secret cryptocurrency wallet helped the DCU's attribution and understanding of their operations. A criminal referral for Ogundipe has been sent to international law enforcement."
</p>

<p>
	 
</p>

<p>
	In May, Microsoft <a href="https://www.bleepingcomputer.com/news/security/lumma-infostealer-malware-operation-disrupted-2-300-domains-seized/" rel="external nofollow" target="_blank">also seized 2,300 domains</a> in a coordinated disruption action targeting the Lumma malware-as-a-service (MaaS) information stealer.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 18 September 2025 at 4:33 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31387</guid><pubDate>Wed, 17 Sep 2025 18:34:26 +0000</pubDate></item><item><title>Apple patches a zero-day threat in older iPhones, iPads</title><link>https://nsaneforums.com/news/security-privacy-news/apple-patches-a-zero-day-threat-in-older-iphones-ipads-r31386/</link><description><![CDATA[<p>
	Apple has released a security update for many older iPhone and iPad models. This update includes a critical security fix, for a zero-day threat.
</p>

<p>
	 
</p>

<p>
	This security update completely went under my radar because I was focusing on iOS 26 and didn't check Apple's security releases page. Speaking of which iOS 26, iPadOS 26, macOS Tahoe 26 all ship with <a data-wpel-link="external" href="https://support.apple.com/en-us/125108" rel="external nofollow" target="_blank">a bunch of new security fixes</a>.
</p>

<p>
	 
</p>

<p>
	Anyway, let's get back to the update for older devices, the vulnerability in question is tracked under CVE-2025-43300. What's interesting about this is that it is the same as <a data-wpel-link="internal" href="https://www.ghacks.net/2025/08/21/apple-releases-fix-for-a-zero-day-threat-in-ios-ipados-and-macos/" rel="external nofollow" target="_blank">the one I wrote about last month.</a> Apple patched a zero-day threat in iOS, iPadOS and macOS on August 20, with the release of iOS 18.6.2, iPadOS 18.6.2, and macOS Sequoia 15.6.1, macOS Sonoma 14.7.8 and macOS Ventura 13.7.8.
</p>

<p>
	 
</p>

<p>
	<a data-wpel-link="external" href="https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-ipads/" rel="external nofollow" target="_blank">Bleeping Computer</a> spotted some security advisories on Apple's website that highlighted the release of iOS 15.8.5, iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12 to patch the vulnerability. Here's a brief description of the issue, processing a malicious image file may result in memory corruption. For instance, a photo with spyware code could lead to a targeted attack. Apple says it patched an out-of-bounds write issue with improved bounds checking. The release notes mentions that "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals." As I said, that is a sophisticated mercenary spyware attack targeting individuals like journalists, activists, etc.
</p>

<p>
	 
</p>

<p>
	The<a data-wpel-link="external" href="https://support.apple.com/en-us/125141" rel="external nofollow" target="_blank"> iOS 16.7.12 update</a> is available for the Phone 8, iPhone 8 Plus, and iPhone X, while the <a data-wpel-link="external" href="https://support.apple.com/en-us/125142" rel="external nofollow" target="_blank">iOS 15.8.5 update</a> is available for iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), and iPod touch (7th generation). iPadOS 16.7.12 is available for the iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation, while iPadOS 15.8.5 is available for the iPad Air 2, iPad Mini (4th generation).
</p>

<p>
	 
</p>

<p>
	It's good to see Apple patching security issues on devices that are nearly ten years old, the iPhone 7 was launched in 2016. Earlier this month, <a data-wpel-link="internal" href="https://www.ghacks.net/2025/09/01/whatsapp-fixes-zero-click-vulnerability-in-ios-and-macos-which-was-used-in-targeted-spyware-attacks/" rel="external nofollow" target="_blank">WhatsApp fixed a zero-click vulnerability</a> in iOS and macOS that was used in similar attacks.
</p>

<p>
	 
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	<a href="https://www.ghacks.net/2025/09/17/apple-patches-zero-day-threats-in-older-iphones-ipads/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 18 September 2025 at 4:33 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31386</guid><pubDate>Wed, 17 Sep 2025 18:33:26 +0000</pubDate></item><item><title>Windows Secure Boot certificates are expiring, here is everything you need know</title><link>https://nsaneforums.com/news/security-privacy-news/windows-secure-boot-certificates-are-expiring-here-is-everything-you-need-know-r31370/</link><description><![CDATA[<p>
	About three months ago, Microsoft published a blog post about <a automate_uuid="757572d2-7865-454e-bdb3-63ba794e4ac2" href="https://www.neowin.net/news/certificates-for-one-of-windows-11s-hardware-requirements-expire-soon-here-is-what-to-know/" rel="external nofollow">expiring Secure Boot certificates</a> and explained why the issue is important and what you need to know about it. Now, as we get closer to the day X, the company has published a new support document with more details about the matter.
</p>

<p>
	 
</p>

<p>
	Microsoft introduced Secure Boot in 2011 as a new method to ensure your computer boots using verified firmware and a trusted bootloader. Years later, Secure Boot became one of Windows 11's hardware requirements alongside Trusted Platform Module as part of Microsoft's push to make devices more secure.
</p>

<p>
	 
</p>

<p>
	The first Secure Boot certificates are valid for 15 years, and they are about to expire in June 2026. Expired certificates are a big deal because, without them, Windows cannot apply certain updates, which leaves your system vulnerable to BootKits and other malware.
</p>

<p>
	 
</p>

<p>
	Updating certificates is not something your average Joe does on a regular basis. As such, Microsoft prepared a detailed FAQ section where it answered all the possible questions about expired certificates and what to do with them. If you own a regular home PC that gets updates via Windows Update, there is pretty much nothing to worry about, as Microsoft will make all the necessary updates in the background (another reason why you should not disable Windows Updates for long periods).
</p>

<p>
	 
</p>

<p>
	If you are on Windows 10 and you do not plan to upgrade to Windows 11, <a automate_uuid="6f042551-ac25-45c8-ad49-f22a11f91b2f" href="https://www.neowin.net/guides/how-to-get-one-more-year-of-windows-10-updates-for-free/" rel="external nofollow">enrolling in the Extended Security Updates program</a> is a must to get updated certificates. The only exception is supported Windows 10 LTSC/LTSB releases, which will continue receiving security updates past October 14, 2025. Microsoft makes it clear that unsupported Windows versions will not get new Secure Boot certificates.
</p>

<p>
	 
</p>

<p>
	The new FAQ section also addresses the question about upgrading Windows 10 LTSC to Windows 11 LTSC with Secure Boot turned off and an expired certificate. Microsoft explains that such devices will not receive new certificates, and users will have to "follow specific migration steps relevant at that time" to ensure their systems have the 2023 certificates.
</p>

<p>
	 
</p>

<p>
	There is another important area that the FAQ document explains, which is about PCs that cannot boot after resetting the firmware. Microsoft explains that systems that already use a boot manager with the 2023 certificates will stop booting if users reset firmware to defaults that do not include the Windows UEFI CA 2023 certificate. This can be mitigated by reapplying the certificate using a recovery USB (explained in detail in <a automate_uuid="0cedd6e0-8d6d-4f6e-a6c2-68fea93bfa58" href="https://support.microsoft.com/en-us/topic/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d#bkmk_windows_install_media" rel="external nofollow">this document</a>).
</p>

<p>
	 
</p>

<p>
	You can read all the questions and answers about expiring Secure Boot certificates in the official document <a automate_uuid="84b88248-ee51-4f2c-9d0a-c6797cbcbb93" href="https://support.microsoft.com/en-us/topic/frequently-asked-questions-about-the-secure-boot-update-process-b34bf675-b03a-4d34-b689-98ec117c7818" rel="external nofollow">here</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/windows-secure-boot-certificates-are-expiring-here-is-everything-you-need-know/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 17 September 2025 at 4:41 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31370</guid><pubDate>Tue, 16 Sep 2025 18:42:07 +0000</pubDate></item><item><title>When will Jaguar Land Rover restart production? &#x201C;No one actually knows.&#x201D;</title><link>https://nsaneforums.com/news/security-privacy-news/when-will-jaguar-land-rover-restart-production-%E2%80%9Cno-one-actually-knows%E2%80%9D-r31369/</link><description><![CDATA[<h3>
	Cyberattack has frozen operations at the company since the end of August.
</h3>

<p>
	Jaguar Land Rover’s dealers and suppliers fear the British carmaker’s operations will take another few months to normalize after a cyber attack that experts estimate could wipe more than £3.5 billion off its revenue.
</p>

<p>
	 
</p>

<p>
	JLR, which is owned by India’s Tata Motors, had been forced to shut down its systems and halt production across its UK factories since August 31, wreaking havoc across the country’s vast supply chain involving roughly 200,000 workers.
</p>

<p>
	 
</p>

<p>
	JLR on Tuesday said it would extend its production halt until at least next Wednesday as it continued its investigation. In a statement, the company also cautioned that “the controlled restart of our global operations… will take time.”
</p>

<p>
	 
</p>

<p>
	If JLR cannot produce vehicles until November, David Bailey, professor at University of Birmingham, estimated that the group would suffer a revenue hit of more than £3.5 billion while it would lose about £250 million in profits, or about £72 million in revenue and £5 million in profits on a daily basis.
</p>

<p>
	 
</p>

<p>
	With annual revenues of £29 billion in 2024, JLR will be able to absorb the financial costs but Bailey warned the consequences would be bigger for the smaller sized companies in its supply chain. JLR declined to comment.
</p>

<p>
	 
</p>

<p>
	The cyber attack comes at a crucial period for the UK carmaker when it is going through a controversial rebranding of its Jaguar brand and an expensive shift to all-electric vehicles by the end of the decade. Even before the latest incident, people briefed on the matter have said the company was facing delays with launching its new electric models.
</p>

<p>
	 
</p>

<p>
	“They are clearly in chaos,” said one industry executive who works closely with JLR, while another warned that “no one actually knows” when production would resume.
</p>

<p>
	 
</p>

<p>
	“If there is a major financial hit, the CEO will look for significant cost savings to try and recover some of that, so that could hit both the production base in the UK but also its product development,” said Bailey.
</p>

<p>
	 
</p>

<p>
	According to people close to the industry, JLR has been helped by an ample inventory of JLR vehicles before the incident, meaning car sales were unaffected after production halted. The company is still able to sell new cars and register them manually.
</p>

<p>
	 
</p>

<p>
	According to online marketplace Auto Trader, JLR took the top slot on its new car platform in August and is vying for a similar position in September with almost a million ad views in the two months.
</p>

<p>
	 
</p>

<p>
	“Despite the well documented issues with the much-loved British brand at the moment, not only is there plenty of stock available but it’s also drawing in the largest audiences in relation to its competitors,” said Ian Plummer, chief commercial officer at Auto Trader.
</p>

<p>
	 
</p>

<p>
	Nevertheless, an immediate challenge for retailers has been their ability to source parts for car repairs. JLR has tried to secure additional supplies in response.
</p>

<p>
	 
</p>

<p>
	The company is also asking UK government officials to provide emergency support for its suppliers to get through this period, according to people close to the talks.
</p>

<p>
	 
</p>

<p>
	While JLR has not provided information on who is responsible for the attack, a hacker calling himself “Rey” has claimed to have infiltrated the carmaker’s systems for the second time in just six months.
</p>

<p>
	 
</p>

<p>
	Cyber experts say they believe “Rey” is the same individual previously linked to the hacker group Hellcat, which claimed to have breached JLR in March and to have stolen confidential data. JLR declined to comment on the previous incident in March.
</p>

<p>
	 
</p>

<p>
	The organization, which uses the same tactics as the “Scattered Spider” collective linked to the high-profile attacks on retailers, including M&amp;S, has previously declared to have attacked companies such as telecoms group Telefónica.
</p>

<p>
	 
</p>

<p>
	The cyber attack at M&amp;S in April forced the retailer to suspend online clothing and homeware sales for seven weeks—a disruption expected to cost up to £300 million in operating profits this year.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/cars/2025/09/when-will-jaguar-land-rover-restart-production-no-one-actually-knows/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 17 September 2025 at 4:39 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31369</guid><pubDate>Tue, 16 Sep 2025 18:40:47 +0000</pubDate></item><item><title>Microsoft commits to European interoperability in a groundbreaking agreement</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-commits-to-european-interoperability-in-a-groundbreaking-agreement-r31330/</link><description><![CDATA[<p>
	Microsoft has finalized an agreement with the European Commission to address competition concerns regarding Teams. The changes are designed to enhance flexibility and give customers more options and commit the company to consumer choice and interoperability in a competitive landscape. The agreement involves changes to licensing and pricing for Microsoft 365, Office 365, and Microsoft Teams.
</p>

<p>
	 
</p>

<p>
	Microsoft is expanding interoperability and data portability resources. It will maintain the existing add-in model for third-party communication and collaboration providers and the AppSource marketplace will remain a distribution channel for these add-ins. The add-in model allows third-party solutions to integrate with Microsoft 365 and Teams in the same way as other software development companies that provide add-ins to Microsoft 365 and Teams.
</p>

<p>
	 
</p>

<p>
	In addition, Microsoft will continue to enable other solution providers to embed Office Web Applications within their own solutions through the Microsoft Document Collaboration Partner Program to better serve shared customers.
</p>

<p>
	 
</p>

<p>
	Microsoft said that the changes are explicitly aimed at enhancing flexibility, supporting open ecosystems, and providing customers with more options. The Redmond giant described partners as trusted advisors who deliver business outcomes and that the overall goal is to drive real impact for customers across their journey with their services and solutions.
</p>

<p>
	 
</p>

<p>
	Source: <a automate_uuid="1eb2d40f-0293-4e5b-9579-0882ffd7b914" href="https://techcommunity.microsoft.com/blog/partnernews/partner-blog--evolving-our-productivity-offerings-to-resolve-european-competitio/4453704" rel="external nofollow">Microsoft</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-commits-to-european-interoperability-in-a-groundbreaking-agreement/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 14 September 2025 at 5:02 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31330</guid><pubDate>Sat, 13 Sep 2025 19:02:59 +0000</pubDate></item><item><title>Plex shares details on user data hack and breach, including how to reset password</title><link>https://nsaneforums.com/news/security-privacy-news/plex-shares-details-on-user-data-hack-and-breach-including-how-to-reset-password-r31258/</link><description><![CDATA[<p>
	Plex, the very popular home media server and streaming platform, has shared a detailed advisory on a recent security incident. The firm has confirmed that an unauthorized third party accessed a "limited subset" of customer data, but that it was able to mitigate the scope of the hack and its impact.
</p>

<p>
	 
</p>

<p>
	Plex has also assured that account passwords that may have been accessed by this breach were securely hashed, so were not read in plaintext by the threat actor.
</p>

<p>
	 
</p>

<p>
	Regardless, the firm has shared details for its customers on how to handle the situation which includes resetting the sign-in password. In addition, it has also recommended that users enable two-factor authentication (2FA), if it isn't already, to further enhance their account's cybersecurity posture. It <a automate_uuid="deb53660-8541-497c-b117-8e7b54ccc219" href="https://forums.plex.tv/t/important-notice-of-security-incident/930523" rel="external nofollow">writes</a><span>:</span>
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		<strong>If you use a password to sign into Plex:</strong> We kindly request that you reset your Plex account password immediately by visiting<a automate_uuid="9d7aacb9-2bd2-4d22-8516-f19a4cbfce68" href="https://plex.tv/reset" rel="external nofollow"> https://plex.tv/reset</a>. When doing so, there’s a checkbox to “Sign out connected devices after password change,” which we recommend you enable. This will sign you out of all your devices (including any Plex Media Server you own) for your security, and you will then need to sign back in with your new password.
	</p>

	<p>
		 
	</p>

	<p>
		<strong>If you use SSO to sign into Plex:</strong> We kindly request that you log out of all active sessions by visiting<a automate_uuid="97348ce5-8f57-41f0-80a5-1e704b8e02cb" href="http://plex.tv/security" rel="external nofollow"> https://plex.tv/security</a> and clicking the button that says ”Sign out of all devices”. This will sign you out of all your devices (including any Plex Media Server you own) for your security, and you will then need to sign back in as normal.
	</p>

	<p>
		 
	</p>

	<p>
		We remind you that <strong>no one at Plex will ever reach out to you over email to ask for a password or credit card number for payments</strong>. For further account protection, we also recommend enabling<a automate_uuid="37ad5421-21a8-415c-aeb5-ec3253cdc106" href="https://support.plex.tv/articles/two-factor-authentication/?utm_source=Plex&amp;utm_medium=email&amp;utm_content=reset_password&amp;utm_campaign=sql_db_password_reset" rel="external nofollow"> two-factor authentication</a> on your Plex account if you haven’t already done so.
	</p>
</blockquote>

<p>
	Finally, the company has shared a support article <a automate_uuid="35dda0ce-0399-4b4f-b02d-39eb3123bd0b" href="https://support.plex.tv/articles/account-requires-password-reset/" rel="external nofollow">at this link</a> which walks users through the steps one by one on how to reset their account password.
</p>

<p>
	 
</p>

<p>
	The company has already been sending out emails to users, but even if you have not received one, it is best advised that you reset your password just to be on the safe side.
</p>

<p>
	 
</p>

<p>
	Some users are also finding that their libraries after the password reset shows up as empty, in which case, you will need to reclaim the server or try the login process a few more times (via <a automate_uuid="354b3d2b-78ab-4ddd-9361-aadd7571970d" href="https://www.reddit.com/r/PleX/comments/1nc0t9n/changed_password_and_boom_all_libraries_show_empty/" rel="external nofollow">Reddit</a>).
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/plex-shares-details-on-user-data-hack-and-breach-including-how-to-reset-password/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 10 September 2025 at 3:57 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31258</guid><pubDate>Tue, 09 Sep 2025 17:57:57 +0000</pubDate></item><item><title>Plex tells users to reset passwords after new data breach</title><link>https://nsaneforums.com/news/security-privacy-news/plex-tells-users-to-reset-passwords-after-new-data-breach-r31244/</link><description><![CDATA[<p>
	Media streaming platform Plex is warning customers to reset passwords after suffering a data breach in which a hacker was able to steal customer authentication data from one of its databases.
</p>

<p>
	 
</p>

<p>
	In a data breach notification seen by BleepingComputer, Plex says the stolen data includes email addresses, usernames, securely hashed passwords, and authentication data.
</p>

<p>
	 
</p>

<p>
	"An unauthorized third party accessed a limited subset of customer data from one of our databases," reads the Plex data breach notification.
</p>

<p>
	 
</p>

<p>
	"While we quickly contained the incident, information that was accessed included emails, usernames, and securely hashed passwords."
</p>

<p>
	 
</p>

<p>
	"Any account passwords that may have been accessed were securely hashed, in accordance with best practices, meaning they cannot be read by a third party."
</p>

<p>
	 
</p>

<p>
	Plex has not shared what hashing algorithm was used, raising the possibility that attackers could attempt to crack the passwords.
</p>

<p>
	 
</p>

<p>
	Therefore, Plex recommends that users, out of an "abundance of caution," reset their password at <a href="https://plex.tv/reset" rel="external nofollow" target="_blank">https://plex.tv/reset</a> and also enable the "Sign out connected devices after password change" option when doing so.
</p>

<p>
	 
</p>

<p>
	This will reset your password and log out any existing connections utilizing your own credentials. However, this will also require you to log in again on any devices using those credentials.
</p>

<p>
	 
</p>

<p>
	For those using SSO to log in to Plex, the company recommends you log out of all active sessions by visiting<a href="http://plex.tv/security" rel="external nofollow" target="_blank"> https://plex.tv/security</a> and clicking the button that says" Sign out of all devices".  Once again, you will need to log back into devices using your credentials.
</p>

<p>
	 
</p>

<p>
	The company is also reminding users to enable two-factor authentication for added protection and stresses that it will never ask for passwords or credit card details over email.
</p>

<p>
	 
</p>

<p>
	Plex says no payment card information was included in the breach, as it's not stored on its server.
</p>

<p>
	 
</p>

<p>
	The company says it has addressed the method used to breach its server, but did not share any further technical details about the attack.
</p>

<p>
	 
</p>

<p>
	BleepingComputer contacted Plex with questions about the breach and will update the article if we hear back.
</p>

<p>
	 
</p>

<p>
	This is not the first time Plex users have been forced to reset their passwords due to a data breach.
</p>

<p>
	 
</p>

<p>
	In August 2022, <a href="https://www.bleepingcomputer.com/news/security/plex-warns-users-to-reset-passwords-after-a-data-breach/" rel="external nofollow" target="_blank">Plex suffered an almost identical data breach</a>, with authentication data and hashed passwords exposed in the attack.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/plex-tells-users-to-reset-passwords-after-new-data-breach/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 9 September 2025 at 1:58 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31244</guid><pubDate>Tue, 09 Sep 2025 03:59:00 +0000</pubDate></item><item><title>Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack</title><link>https://nsaneforums.com/news/security-privacy-news/hackers-hijack-npm-packages-with-2-billion-weekly-downloads-in-supply-chain-attack-r31243/</link><description><![CDATA[<p>
	In a supply chain attack, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising a maintainer's account in a phishing attack.
</p>

<p>
	 
</p>

<p>
	Josh Junon (<a href="https://www.npmjs.com/~qix" rel="external nofollow" target="_blank">qix</a>), the package maintainer whose accounts were hijacked in this supply-chain attack, <a href="https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y" rel="external nofollow" target="_blank">confirmed</a> the incident earlier today, stating that he was aware of the compromise and adding that the phishing email came <a href="https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydje4zqis2y" rel="external nofollow" target="_blank">from support [at] npmjs [dot] help</a>, a domain that hosts a website impersonating the legitimate npmjs.com domain.
</p>

<p>
	 
</p>

<p>
	In the emails, the attackers threatened that the targeted maintainers' accounts would be locked on September 10th, 2025, as a scare tactic to get them to click on the link redirecting them to the phishing sites.
</p>

<p>
	 
</p>

<p>
	"As part of our ongoing commitment to account security, we are requesting that all users update their Two-Factor Authentication (2FA) credentials. Our records indicate that it has been over 12 months since your last 2FA update," the phishing email reads.
</p>

<p>
	 
</p>

<p>
	"To maintain the security and integrity of your account, we kindly ask that you complete this update at your earliest convenience. Please note that accounts with outdated 2FA credentials will be temporarily locked starting September 10, 2025, to prevent unauthorized access."
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Phishing email" class="ipsImage" height="720" width="710" src="https://www.bleepstatic.com/images/news/u/1109292/2025/phishing-email.jpg">
		<figcaption>
			<em>Phishing email (<a href="https://github.com/Marsup" rel="external nofollow" target="_blank">Nicolas Morel</a>)</em>
		</figcaption>
	</figure>
</div>

<p>
	The attackers targeted other package maintainers and developers using the same email, according to <a href="https://github.com/orgs/community/discussions/172738" rel="external nofollow" target="_blank">reports</a> from those who received the phishing message.
</p>

<p>
	 
</p>

<p>
	BleepingComputer found that the npmjs[.]help page also includes a login form that will exfiltrate inputted credentials to the following URL:
</p>

<pre><code>https://websocket-api2[.]publicvm.com/images/jpg-to-png.php?name=[name]&amp;pass=[password]</code></pre>

<p>
	Since the incident was detected, the NPM team has removed some of the malicious versions published by the attackers, including the one for the debug package, which is downloaded 357.6 million times per week.
</p>

<p>
	 
</p>

<p>
	<a href="https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydmyzpwa22s" rel="external nofollow" target="_blank"><img alt="Josh Junon skeet" class="ipsImage" height="328" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Josh_Junon_skeet.png"></a>
</p>

<h2>
	The supply chain attack
</h2>

<p>
	According to Aikido Security, which <a href="https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised" rel="external nofollow" target="_blank">analyzed the supply-chain attack</a>, the threat actors updated the packages after taking over control, injecting malicious code that acts as a browser-based interceptor into the index.js files, capable of hijacking network traffic and application APIs.
</p>

<p>
	 
</p>

<p>
	The malicious code only impacts individuals accessing the compromised applications over the web, monitoring for cryptocurrency addresses and transactions that are then redirected to attacker-controlled wallet addresses. This causes the transaction to be hijacked by the attackers rather than being sent to the intended address.
</p>

<p>
	 
</p>

<p>
	The malware operates <a href="https://github.com/chalk/chalk/issues/656#issuecomment-3266894253" rel="external nofollow" target="_blank">by injecting itself into the web browser</a>, monitoring Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash wallet addresses or transfers. On network responses with crypto transactions, it replaces the destinations with attacker-controlled addresses and hijacks transactions before they're signed.
</p>

<p>
	 
</p>

<p>
	Aikido says the malicious code does this by hooking JavaScript functions like <code>fetch</code>, <code>XMLHttpRequest</code>, and wallet APIs (window.ethereum, Solana, etc.).
</p>

<p>
	 
</p>

<p>
	The packages hijacked so far collectively have over 2.6 billion downloads every week:
</p>

<p>
	 
</p>

<ul style="list-style-type:square">
	<li>
		backslash (0.26m downloads per week)
	</li>
	<li>
		chalk-template (3.9m downloads per week)
	</li>
	<li>
		supports-hyperlinks (19.2m downloads per week)
	</li>
	<li>
		has-ansi (12.1m downloads per week)
	</li>
	<li>
		simple-swizzle (26.26m downloads per week)
	</li>
	<li>
		color-string (27.48m downloads per week)
	</li>
	<li>
		error-ex (47.17m downloads per week)
	</li>
	<li>
		color-name (191.71m downloads per week)
	</li>
	<li>
		is-arrayish (73.8m downloads per week)
	</li>
	<li>
		slice-ansi (59.8m downloads per week)
	</li>
	<li>
		color-convert (193.5m downloads per week)
	</li>
	<li>
		wrap-ansi (197.99m downloads per week)
	</li>
	<li>
		ansi-regex (243.64m downloads per week)
	</li>
	<li>
		supports-color (287.1m downloads per week)
	</li>
	<li>
		strip-ansi (261.17m downloads per week)
	</li>
	<li>
		chalk (299.99m downloads per week)
	</li>
	<li>
		debug (357.6m downloads per week)
	</li>
	<li>
		ansi-styles (371.41m downloads per week)
	</li>
</ul>

<p>
	 
</p>

<p>
	"The packages were updated to contain a piece of code that would be executed on the client of a website, which silently intercepts crypto and web3 activity in the browser, manipulates wallet interactions, and rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user," Aikido Security researcher Charlie Eriksen said.
</p>

<p>
	 
</p>

<p>
	"What makes it dangerous is that it operates at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users' apps believe they are signing."
</p>

<p>
	 
</p>

<p>
	While this is a supply chain attack, Andrew MacPherson, Principal Security Engineer at Privy, told BleepingComputer that there are specific criteria that must be met for an app to have been affected, which significantly decreases the impact. This includes:
</p>

<p>
	 
</p>

<ul data-border="0" data-indent="0" data-list-tree="true" data-stringify-type="unordered-list" style="list-style-type:square">
	<li data-stringify-border="0" data-stringify-indent="0">
		A fresh install between ~9 AM and ~11.30 AM ET, when the packages were compromised
	</li>
	<li data-stringify-border="0" data-stringify-indent="0">
		Package-lock.json was created during that time
	</li>
	<li data-stringify-border="0" data-stringify-indent="0">
		Vulnerable packages in direct or transient dependencies
	</li>
</ul>

<p>
	 
</p>

<p>
	This supply-chain attack follows a series of similar attacks targeting developers of various well-known JavaScript libraries over the past few months.
</p>

<p>
	 
</p>

<p>
	For instance, in July, attackers <a href="https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/" rel="external nofollow" target="_blank">compromised eslint-config-prettier</a>, a package with over 30 million weekly downloads, while in March, <a href="https://www.bleepingcomputer.com/news/security/infostealer-campaign-compromises-10-npm-packages-targets-devs/" rel="external nofollow" target="_blank">ten other widely used npm libraries</a> were hijacked and turned into info-stealers.
</p>

<p>
	 
</p>

<p>
	Both the phishing attack and the injected malware illustrate how the web browser has become a massive attack surface for stealing credentials, modifying traffic, and breaching networks.
</p>

<p>
	 
</p>

<p>
	BleepingComputer has a webinar later this month titled "<a href="https://www.scworld.com/cybercast/your-browser-is-the-breach-securing-the-modern-web-edge?utm_source=partner-campaign&amp;utm_medium=bc_npm_sca&amp;utm_campaign=sc-cybercast-bleepingcomputer-2025-september" rel="external nofollow" target="_blank">Your Browser Is the Breach: Securing the Modern Web Edge</a>" that focuses on recent browser attacks and how to defend this attack surface.
</p>

<p>
	 
</p>

<p>
	<em>Update: Revised the lede as the attack is not as impactful as initially thought.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-npm-packages-with-2-billion-weekly-downloads-in-supply-chain-attack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 9 September 2025 at 1:57 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31243</guid><pubDate>Tue, 09 Sep 2025 03:57:48 +0000</pubDate></item><item><title>UK to strengthen online safety laws to protect vulnerable adults</title><link>https://nsaneforums.com/news/security-privacy-news/uk-to-strengthen-online-safety-laws-to-protect-vulnerable-adults-r31237/</link><description><![CDATA[<p>
	The UK government has announced that it’s introducing new laws to toughen the <a automate_uuid="e6c71586-4127-47f6-90ec-f1f259c67121" href="https://www.neowin.net/news/uk-enforces-strict-new-online-age-checks-today/" rel="external nofollow">Online Safety Act</a> with the goal of protecting vulnerable people of all ages from content that encourages or assists self-harm. The government described this as an urgent action that’s intended to prevent users from being exposed to “devastating” self-harm material. While existing protections are aimed at children, the new rules will strive to protect adults with mental health issues.
</p>

<p>
	 
</p>

<p>
	With <a automate_uuid="ab32a4de-75c4-4fe7-ab97-ca4cecb78036" href="https://www.gov.uk/government/news/online-safety-laws-to-strengthen-to-protect-people-of-all-ages-from-devastating-self-harm-content" rel="external nofollow">this change</a>, any material that encourages or assists serious self-harm will be classified as a priority offense that needs to be addressed to protect children and adults. The new regulations are expected to be laid out in the autumn and will come into force 21 days after being approved.
</p>

<p>
	 
</p>

<p>
	Under the new rules, tech firms will be legally required to hunt down and remove self-harm material using “cutting-edge technology” to see out self-harm content before it can reach users. This shift is designed to change moderation from a reactive approach to a proactive one, compelling companies to prevent harm, not just respond to it. The Technology Secretary Liz Kendall said that these new requirements are “not an option, but the law.”
</p>

<p>
	 
</p>

<p>
	It’s not just the government that’s eager to introduce the new rules. The Chief Executive of the Samaritans, Julie Bentley, welcomed the new measures. The Samaritans view the changes as a positive step that can ensure the Online Safety Act goes further to protect both adults and children. Bentley said that while the internet can offer support for people who are struggling, it can also be used to find self-harm content that can be fatal.
</p>

<p>
	 
</p>

<p>
	With this change, the government is responding to the consequences that self-harm content has had time and time again, which can “destroy lives and tear families apart.” For adults, the new rules are intended to prevent content that could trigger a mental health crisis or worse. The government said that the regulations will be brought into force as a Statutory Instrument (SI) and require approval by both Houses of Parliament. The rules will come into force 21 days after implementation.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/uk-to-strengthen-online-safety-laws-to-protect-vulnerable-adults/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 9 September 2025 at 3:08 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31237</guid><pubDate>Mon, 08 Sep 2025 17:09:26 +0000</pubDate></item><item><title>AI-powered malware hit 2,180 GitHub accounts in &#x201C;s1ngularity&#x201D; attack</title><link>https://nsaneforums.com/news/security-privacy-news/ai-powered-malware-hit-2180-github-accounts-in-%E2%80%9Cs1ngularity%E2%80%9D-attack-r31215/</link><description><![CDATA[<p>
	Investigations into the Nx "s1ngularity" NPM supply chain attack have unveiled a massive fallout, with thousands of account tokens and repository secrets leaked.
</p>

<p>
	 
</p>

<p>
	According to a post-incident <a href="https://www.wiz.io/blog/s1ngularitys-aftermath" rel="external nofollow" target="_blank">evaluation by Wiz researchers</a>, the Nx compromise has resulted in the exposure of 2,180 accounts and 7,200 repositories across three distinct phases.
</p>

<p>
	 
</p>

<p>
	Wiz also stressed that the incident's scope of impact remains significant, as many of the leaked secrets remain valid, and so the effect is still unfolding.
</p>

<h2>
	The Nx "s1ngularity" supply chain attack
</h2>

<p>
	Nx is a popular open-source build system and monorepo management tool, widely used in enterprise-scale JavaScript/TypeScript ecosystems, having over 5.5 million weekly downloads on the NPM package index.
</p>

<p>
	 
</p>

<p>
	On August 26, 2025, attackers exploited a flawed GitHub Actions workflow in the Nx repository to publish a malicious version of the package on NPM, which included a post-install malware script ('telemetry.js').
</p>

<p>
	 
</p>

<p>
	The telemetry.js malware is a credential stealer targeting Linux and macOS systems, which attempted to steal GitHub tokens, npm tokens, SSH keys, .env files, crypto wallets, and upload the secrets to public GitHub repositories named "s1ngularity-repository."
</p>

<p>
	 
</p>

<p>
	What made this attack stand out was that the credential-stealer to used installed command-line tools for artificial intelligence platforms, such as Claude, Q, and Gemini, to search for and harvest sensitive credentials and secrets using LLM prompts.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="LLM prompt to search for and steal credentials and other secrets" class="ipsImage" height="290" width="720" src="https://www.bleepstatic.com/images/news/security/n/nx-supply-chain-attack/llm-prompt-to-steal-credentials.jpg">
		<figcaption>
			<em>LLM prompt to search for and steal credentials and other secrets<br>
			Source: Wiz</em>
		</figcaption>
	</figure>
</div>

<p>
	Wiz reports that the prompt changed over each iteration of the attack, showing that the threat actor was tuning the prompt for better success.
</p>

<p>
	 
</p>

<p>
	"The evolution of the prompt shows the attacker exploring prompt tuning rapidly throughout the attack. We can see the introduction of <a href="https://learnprompting.org/docs/basics/roles" rel="external nofollow"><u>role-prompting</u></a>, as well as varying levels of specificity on techniques," explained Wiz.
</p>

<p>
	 
</p>

<p>
	"These changes had a concrete impact on the success of the malware. The introduction of the phrase “penetration testing”, for example, was concretely reflected in LLM refusals to engage in such activity."
</p>

<h2>
	A massive blast radius
</h2>

<p>
	In the first phase of the attack, between August 26 and 27, the backdoored Nx packages directly impacted 1,700 users, leaking over 2,000 unique secrets. The attack also exposed 20,000 files from infected systems.
</p>

<p>
	 
</p>

<p>
	GitHub responded by taking down the repositories the attacker created after eight hours, but the data had already been copied.
</p>

<p>
	 
</p>

<p>
	Between August 28 and 29, which Wiz defines as phase 2 of the incident, the attackers used the leaked GitHub tokens to flip private repositories to public, renaming them to include the 's1ngularity' string.
</p>

<p>
	 
</p>

<p>
	This has resulted in the further compromise of another 480 accounts, the majority of which were organizations, and the public exposure of 6,700 private repositories.
</p>

<p>
	 
</p>

<p>
	In the third phase, which began on August 31, the attackers targeted a single victim organization, utilizing two compromised accounts to publish an additional 500 private repositories.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Overview of attack and impact" class="ipsImage" height="393" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/September/overview.jpg">
		<figcaption>
			<em>Overview of the s1ngularity attack<br>
			Source: Wiz</em>
		</figcaption>
	</figure>
</div>

<h2>
	Nx's response
</h2>

<p>
	The Nx team published a detailed <a href="https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c" rel="external nofollow" target="_blank">root cause analysis</a> on GitHub explaining that the compromise came from a pull request title injection combined with the insecure use of pull_request_target.
</p>

<p>
	 
</p>

<p>
	This allowed the attackers to run arbitrary code with elevated permissions, which in turn triggered Nx's publish pipeline and exfiltrated the npm publishing token.
</p>

<p>
	 
</p>

<p>
	The malicious packages were removed, the compromised tokens were revoked and rotated, and two-factor authentication has been adopted across all publisher accounts.
</p>

<p>
	 
</p>

<p>
	To prevent a recurrence of such a compromise, the Nx project has now adopted NPM's Trusted Publisher model, which eliminates token-based publishing, and added manual approval for PR-triggered workflows.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/ai-powered-malware-hit-2-180-github-accounts-in-s1ngularity-attack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 7 September 2025 at 2:16 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31215</guid><pubDate>Sun, 07 Sep 2025 04:17:11 +0000</pubDate></item><item><title>Hovering over links in emails is still one of the best defenses you have against phishing</title><link>https://nsaneforums.com/news/security-privacy-news/hovering-over-links-in-emails-is-still-one-of-the-best-defenses-you-have-against-phishing-r31203/</link><description><![CDATA[<p>
	Phishing and its many variants are still a major threat on today's Internet. Email phishing is still a dominant attack type. You receive an email that usually claims to come from a legitimate company or service, in order to steal your passwords, other data, or gain access to information.
</p>

<p>
	 
</p>

<p>
	Experienced Internet users may detect most phishing emails immediately. One look at the sender's email address or the content of the email, and they know whether it is legitimate or not. Yes, a deep dive into the mail headers is usually the better option to determine whether an email is real or fake, but often, that is not necessary. If you get a claim from a company that you do not do business with, you can almost be certain that the email that you received is not legitimate.
</p>

<p>
	 
</p>

<p>
	Decade-old best practices against phishing still reign supreme. Do not click on links, do not use information to call someone, send them a message, or open a website listed in the phishing email. Bad grammar or spelling used to be a good indicator, but the increased use of AI by threat actors is eliminating most of that in emails.
</p>

<p>
	 
</p>

<p>
	If you are unsure, you may also hover with the mouse over links in phishing emails. At least on desktop systems, you see the link target. Often, it is a destination that has nothing to do with the entity the email supposedly came from. Even if an URL shortener is used or a new strategy is implemented, <a data-wpel-link="external" href="https://www.malwarebytes.com/blog/news/2025/08/facebook-users-targeted-in-login-phish" rel="external nofollow" target="_blank">like showing mailto links</a> instead of web links, it should ring the alarm bells loud and clear immediately.
</p>

<p>
	 
</p>

<p>
	On mobile, you may be able to long-press on links to display a context menu with options or information. There is still the risk of accidentally opening a link that you want to check though.
</p>

<p>
	 
</p>

<p>
	The following email, for example, has quite a few red flags. The sender claims that the recipient has to pay customs duties for a parcel transported by DHL.
</p>

<p>
	 
</p>

<p>
	<img alt="Phishing Emails check" class="ipsImage" decoding="async" height="720" width="720" src="https://www.ghacks.net/wp-content/uploads/2025/08/phishing-emails-hover-scaled.png">
</p>

<p>
	 
</p>

<p>
	Apart from the sender's email, it is the link that provides you with additional information. It screams fake, and if you used DHL before, you know that the company does not use the t.co URL shortening service.
</p>

<p>
	 
</p>

<p>
	Hovering over links may give help you distinguish fake emails from real ones. I still recommend that you open links manually only. If you get an email from your bank, a shopping site, or any other service or site that you use, you could still open it manually in your browser instead of clicking on a link, if you believe that there is a high chance that the email is legitimate.
</p>

<p>
	 
</p>

<p>
	<em>Now You: How do you handle the threat of phishing? Do you use specialized security tools to protect against phishing attacks? Feel free to leave a comment down below.</em>
</p>

<p>
	 
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	<a href="https://www.ghacks.net/2025/09/03/hovering-over-links-in-emails-is-still-one-of-the-best-defenses-you-have-against-phishing/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 6 September 2025 at 3:34 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31203</guid><pubDate>Fri, 05 Sep 2025 17:35:27 +0000</pubDate></item><item><title>Chess.com confirms data breach</title><link>https://nsaneforums.com/news/security-privacy-news/chesscom-confirms-data-breach-r31202/</link><description><![CDATA[<p>
	Chess.com is a very popular service that enables people to play chess with each other online, while also offering a social forum for communities and a news section that keeps players updated on the latest in the sport. It has over a hundred million users, who play millions of games daily collectively. For example, right now, the counter at the top of the website shows that roughly 20 million games have been played today, and almost 200,000 people are online simultaneously. Now, the platform has disclosed a data breach affecting some players.
</p>

<p>
	 
</p>

<p>
	As reported by <a automate_uuid="198605ef-4510-4220-a654-e0cf185e600e" href="https://www.bleepingcomputer.com/news/security/chesscom-discloses-recent-data-breach-via-file-transfer-app/" rel="external nofollow">Bleeping Computer</a>, Chess.com has sent notifications to some customers informing them that the service was indirectly impacted in a data breach that affected a third-party file transfer app that was used by the platform. This incident occurred between June 5 and June 18 this year, with the company finding out about the breach on June 19.
</p>

<p>
	 
</p>

<p>
	Chess.com immediately notified relevant law enforcement authorities and solicited security experts to assess the scope of the breach and contain it. It was successful in this process, but the data of almost 4,500 users was exposed. This likely included personally identifiable information (PII), but no financial data was accessed.
</p>

<p>
	 
</p>

<p>
	On a platform boasting 100 million users, 4,500 may sound like a small figure since it only encompasses 0.0045% of its customers. However, the service is still giving impacted customers a couple of years of identity theft and credit monitoring services. Those affected have until December 3, 2025, to enroll in the complimentary services. Chess.com has emphasized that only the third-party file transfer app it used was impacted; its own infrastructure remains robust and unaffected. It's unclear which app was breached, but it's encouraging for now that the stolen data has not been spotted online or identified as being misused by malicious actors.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/chesscom-confirms-data-breach/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 6 September 2025 at 3:33 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31202</guid><pubDate>Fri, 05 Sep 2025 17:34:32 +0000</pubDate></item><item><title>EU fines Google $3.5 billion for anti-competitive ad practices</title><link>https://nsaneforums.com/news/security-privacy-news/eu-fines-google-35-billion-for-anti-competitive-ad-practices-r31201/</link><description><![CDATA[<p>
	The European Commission has fined Google €2.95 billion ($3.5 billion) for abusing its dominance in the digital advertising technology market and favoring its adtech services over those of its competitors.
</p>

<p>
	 
</p>

<p>
	Google was also ordered by the EU's top antitrust regulator to stop anti-competitive and "self-preferencing" practices and take measures to mitigate future conflicts of interest in the adtech market.
</p>

<p>
	 
</p>

<p>
	Lee-Anne Mulholland, Google's Global Head of Regulatory Affairs, told BleepingComputer that the antitrust regulator's decision was wrong and that the company will appeal it.
</p>

<p>
	 
</p>

<p>
	"The European Commission's decision about our ad tech services is wrong and we will appeal. It imposes an unjustified fine and requires changes that will hurt thousands of European businesses by making it harder for them to make money," Mulholland said.
</p>

<p>
	 
</p>

<p>
	"There's nothing anticompetitive in providing services for ad buyers and sellers, and there are more alternatives to our services than ever before."
</p>

<p>
	 
</p>

<p>
	This follows the Commission's <a href="https://ec.europa.eu/commission/presscorner/detail/cs/ip_23_3207" rel="external nofollow" target="_blank">notification to Google</a> in June 2023 of a preliminary finding that its abusive practices in online advertising technology violated the European Union's antitrust rules concerning adtech operations. At the time, <a href="https://blog.google/around-the-globe/google-europe/todays-european-commission-announcement-about-our-advertising-technology/" rel="external nofollow" target="_blank">Google stated</a> that the Commission's case "rests on flawed interpretations of the ad tech sector."
</p>

<p>
	 
</p>

<p>
	This is the fourth time the European Commission has fined Google for abusing its market dominance. In March 2019, the Commission <a href="https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/" rel="external nofollow" target="_blank">fined Google €1.49 billion ($1.7 billion)</a> for blocking rival advertising companies from displaying search ads on publisher search results pages.
</p>

<p>
	 
</p>

<p>
	In July 2018, Google was fined <a href="https://www.bleepingcomputer.com/news/google/google-fined-2-7-billion-for-tweaking-search-results/" rel="external nofollow" target="_blank">€2.42 billion ($2.72 billion)</a> for preventing other companies from competing in the online search and comparison shopping market by abusing its search engine dominance.
</p>

<p>
	 
</p>

<p>
	One year earlier, in June 2017, the EU's competition watchdog imposed <a href="https://www.bleepingcomputer.com/news/google/eu-fines-google-5-billion-for-breaching-antitrust-rules-in-android/" rel="external nofollow" target="_blank">a record €4.34 billion ($5.04 billion) fine</a> on Google "for illegal practices regarding Android mobile devices to strengthen the dominance of Google's search engine."
</p>

<p>
	 
</p>

<p>
	On Wednesday, the National Commission on Informatics and Liberty (CNIL), France's data protection authority, <a href="https://www.bleepingcomputer.com/news/security/france-slaps-google-with-325m-fine-for-violating-cookie-regulations/" rel="external nofollow" target="_blank">also fined Google €325 million ($378 million)</a> for displaying ads between Gmail users' emails without their consent and violating cookie regulations.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/google/eu-fines-google-35-billion-for-anti-competitive-ad-practices/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 6 September 2025 at 3:30 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31201</guid><pubDate>Fri, 05 Sep 2025 17:31:00 +0000</pubDate></item><item><title>New TP-Link zero-day surfaces as CISA warns other flaws are exploited</title><link>https://nsaneforums.com/news/security-privacy-news/new-tp-link-zero-day-surfaces-as-cisa-warns-other-flaws-are-exploited-r31181/</link><description><![CDATA[<p>
	TP-Link has confirmed the existence of an unpatched zero-day vulnerability impacting multiple router models, as CISA warns that other router flaws have been exploited in attacks.
</p>

<p>
	 
</p>

<p>
	The zero-day vulnerability was discovered by independent threat researcher Mehrun (ByteRay), <a href="https://blog.byteray.co.uk/zero-day-alert-automated-discovery-of-critical-cwmp-stack-overflow-in-tp-link-routers-0bc495a08679" rel="external nofollow" target="_blank">who noted</a> that he first reported it to TP-Link on May 11, 2024.
</p>

<p>
	 
</p>

<p>
	The Chinese networking equipment giant confirmed to BleepingComputer that it is currently investigating the exploitability and exposure of the flaw.
</p>

<p>
	 
</p>

<p>
	Though a patch is reportedly already developed for European models, work is underway to develop fixes for U.S. and global firmware versions, with no specific date estimates given.
</p>

<p>
	 
</p>

<p>
	“TP-Link is aware of the recently disclosed vulnerability affecting certain router models, as reported by ByteRay,” reads the statement TP-Link Systems Inc. sent to BleepingComputer.
</p>

<p>
	 
</p>

<p>
	“We take these findings seriously and have already developed a patch for impacted European models. Work is currently underway to adapt and expedite updates for U.S. and other global versions.”
</p>

<p>
	 
</p>

<p>
	“Our technical team is also reviewing the reported findings in detail to confirm device exposure criteria and deployment conditions, including whether CWMP is enabled by default.”
</p>

<p>
	 
</p>

<p>
	“We strongly encourage all users to keep their devices updated with the latest firmware as it becomes available via our official support channels.”
</p>

<p>
	 
</p>

<p>
	The vulnerability, which doesn’t have a CVE-ID assigned to it yet, is a stack-based buffer overflow in TP-Link’s CWMP (CPE WAN Management Protocol) implementation on an unknown number of routers.
</p>

<p>
	 
</p>

<p>
	Researcher Mehrun, who found the flaw through automated taint analysis of router binaries, explains that it lies in a function that handles SOAP SetParameterValues messages.
</p>

<p>
	 
</p>

<p>
	The problem is caused by a lack of bounds checking in ‘strncpy’ calls, making it possible to achieve remote code execution via buffer overflow when the stack buffer size is above 3072 bytes.
</p>

<p>
	 
</p>

<p>
	Mehrun says a realistic attack would be to redirect vulnerable devices to a malicious CWMP server and then deliver the oversized SOAP payload to trigger the buffer overflow.
</p>

<p>
	 
</p>

<p>
	This is achievable by exploiting flaws in outdated firmware or accessing the device by using default credentials that the users haven’t changed.
</p>

<p>
	 
</p>

<p>
	Once compromised via RCE, the router can be instructed to reroute DNS queries to malicious servers, silently intercept or manipulate unencrypted traffic, and inject malicious payloads into web sessions.
</p>

<p>
	 
</p>

<p>
	The researcher confirmed through testing that TP-Link Archer AX10 and Archer AX1500 use vulnerable CWMP binaries. Both are highly popular router models that are currently available for sale in multiple markets.
</p>

<p>
	 
</p>

<p>
	Mehrun also noted that EX141, Archer VR400, TD-W9970, and possibly several other router models from TP-Link are potentially affected.
</p>

<p>
	 
</p>

<p>
	Until TP-Link determines which devices are vulnerable and releases fixes for them, users should change default admin passwords, disable CWMP if not needed, and apply the latest firmware update for their device. If possible, segment the router from critical networks.
</p>

<h2>
	CISA warns of exploited TP-Link flaws
</h2>

<p>
	Yesterday, <a href="https://www.cisa.gov/news-events/alerts/2025/09/03/cisa-adds-two-known-exploited-vulnerabilities-catalog" rel="external nofollow" target="_blank">CISA added two other TP-Link flaws</a>, tracked CVE-2023-50224 and CVE-2025-9377, to the Known Exploited Vulnerability catalog that the Quad7 botnet has exploited to compromise routers.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.cve.org/CVERecord?id=CVE-2023-50224" rel="external nofollow" target="_blank">CVE-2023-50224</a> is an authentication bypass flaw, and <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9377" rel="external nofollow" target="_blank">CVE-2025-9377</a> is a command injection flaw. When chained together, they allow threat actors to gain remote code execution on vulnerable TP-Link devices.
</p>

<p>
	 
</p>

<p>
	Since 2023, the <a href="https://www.bleepingcomputer.com/news/security/quad7-botnet-targets-more-soho-and-vpn-routers-media-servers/" rel="external nofollow" target="_blank">Quad7 botnet has been exploiting the flaws</a> to install custom malware on routers that convert them into proxies and traffic relays.
</p>

<p>
	 
</p>

<p>
	Chinese threat actors have been using these compromised routers to proxy, or relay, malicious attacks while blending in with legitimate traffic to evade detection.
</p>

<p>
	 
</p>

<p>
	In 2024, <a href="https://www.bleepingcomputer.com/news/security/microsoft-chinese-hackers-use-quad7-botnet-to-steal-credentials/" rel="external nofollow" target="_blank">Microsoft observed</a> threat actors using the botnet to perform password spray attacks on cloud services and Microsoft 365, aiming to steal credentials.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/new-tp-link-zero-day-surfaces-as-cisa-warns-other-flaws-are-exploited/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 5 September 2025 at 3:20 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of August): 4,048</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">31181</guid><pubDate>Thu, 04 Sep 2025 17:21:34 +0000</pubDate></item></channel></rss>
