<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/2/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Forget Google Chrome, Brave makes new official bypass to support uBlock Origin and more</title><link>https://nsaneforums.com/news/security-privacy-news/forget-google-chrome-brave-makes-new-official-bypass-to-support-ublock-origin-and-more-r35699/</link><description><![CDATA[<h3>
	Brave's new feature allows you to easily keep using uBlock Origin and other such extensions. And there is Firefox, too, of course.
</h3>

<p>
	Almost exactly a month ago, we learned that Google Chrome will be removing a bunch of Manifest V2 (MV2) extensions once and for all, as even known bypasses to use popular add-ons like uBlock Origin <a href="https://www.neowin.net/news/google-chrome-is-killing-all-ublock-origin-bypasses-microsoft-edge-opera-to-follow/" rel="external nofollow">would stop working</a>.
</p>

<p>
	 
</p>

<p>
	Currently, Chrome is on version 150, and as such, some of those workarounds are already on their way out, although there are still ways to keep using MV2-based extensions like uBlock Origin. We published a detailed guide on that, which you can find <a href="https://www.neowin.net/reports/how-to-roll-back-chrome-and-restore-mv2-extensions-following-the-v150-update/" rel="external nofollow">at this link</a>.
</p>

<p>
	 
</p>

<p>
	However, with the upcoming version 151, Chromium will completely remove all MV2 add-on support and remove them from the Web Store by <a href="https://developer.chrome.com/docs/extensions/develop/migrate/mv2-deprecation-timeline#aug_31st_2026_all_remaining_manifest_v2_extensions_removed_from_the_chrome_web_store" rel="external nofollow">August 31 2026</a>. This means Google's Chrome browser will be totally rid of all such extensions, including the beloved uBlock Origin, among others.
</p>

<p>
	 
</p>

<p>
	If you are an affected user, possibly the best course of action after this will be to jump onto Mozilla's Firefox. The Chrome rival has been supporting Manifest V2, as moving to MV3 is still completely optional. This means you can use uBlock Origin and other such add-ons worry-free, for a while at least. Plus, Firefox is soon getting a new UI overhaul too, and many new useful features, which means you may well quite enjoy the switch. You can check out the <a href="https://www.neowin.net/news/mozilla-highlights-firefox-nova-2026-redesign-and-more-upcoming-features-with-new-roadmap/" rel="external nofollow">details in this article here</a>.
</p>

<p>
	 
</p>

<p>
	If you want to stick to Chromium-based browsers only, assuming you care about the underlying engine (Firefox is Gecko-based), then Brave is a great alternative; and with the latest update released last week, the firm has made an underlying change to add a new ability to automatically detect and replace known Web Store MV2 extensions with Brave-hosted equivalents.
</p>

<p>
	 
</p>

<p>
	Thanks to this effort, users will no longer find their MV2 extensions disabled, and they will no longer be prompted to manually find and install the Brave equivalents. The newest update to the browser, version 1.92.134, added this useful feature.
</p>

<p>
	 
</p>

<p>
	So if you are on an older version of Brave and are finding that some of the extensions you use daily are disabled, you will need to update. You can download it from the <a href="https://www.neowin.net/news/brave-browser-192134/" rel="external nofollow">Neowin software stories page</a>.
</p>

<p>
	 
</p>

<p>
	Other options are Opera, though the <a href="https://www.neowin.net/news/google-chrome-is-killing-all-ublock-origin-bypasses-microsoft-edge-opera-to-follow/#:~:text=coming%20slowly%20but%20surely" rel="external nofollow">company recently stated</a> that eventually, it will move to MV3, so it's not a long-term solution.
</p>

<p>
	 
</p>

<p>
	Finally, there is Microsoft's Edge, and so far, the company has not announced when bypasses will stop working, as it's still labelled as "TBD" (short for To Be Determined). However, it does <a href="https://learn.microsoft.com/en-us/microsoft-edge/extensions/developer-guide/manifest-v3" rel="external nofollow">state</a> that MV2 extensions "will continue to be supported through <a href="https://www.neowin.net/news/official-windows-registry-hack-extends-ublock-origin-support-on-google-chrome-edge/" rel="external nofollow">Enterprise policies</a> at least until the date in the Chromium Manifest V2 support timeline."
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/forget-google-chrome-brave-makes-new-official-bypass-to-support-ublock-origin-and-more/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 8 July 2026 at 6:22 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35699</guid><pubDate>Wed, 08 Jul 2026 08:23:36 +0000</pubDate></item><item><title>Be careful entering one-time codes in Microsoft's login flow, you could be getting phished</title><link>https://nsaneforums.com/news/security-privacy-news/be-careful-entering-one-time-codes-in-microsofts-login-flow-you-could-be-getting-phished-r35676/</link><description><![CDATA[<h3>
	Kaspersky has monitored a new phishing campaign where users put one-time codes into Microsoft's legit login flow, giving attackers account access.
</h3>

<p>
	Kaspersky has outlined quite an interesting phishing campaign that utilizes Microsoft’s infrastructure while making the advice to double-check the domain name redundant. In this new attack, attackers are telling victims to put data directly into a legitimate and trusted corporate site, Microsoft Identity Platform, which supports the OAuth 2.0 spec Device Authorization Grant.
</p>

<p>
	 
</p>

<p>
	According to the security company, the protocol was designed to make it easier to log in on smart TVs, IoT hardware, printers, and other input-constrained devices where typing is hard. The protocol requires users to enter a one-time code on an authentication page, but it is vulnerable to Device Code Phishing.
</p>

<p>
	 
</p>

<p>
	Kaspersky <a href="https://securelist.com/microsoft-device-code-phishing-attack/120350/" rel="external nofollow">said</a> it monitored one of these types of phishing campaigns between April and May this year where attackers sent an email styled as a notice from a law firm. The email had a password-protected PDF file attached. After the victim opened the PDF and entered a password to open the file, they saw several documents which could be opened by clicking on a link.
</p>

<p>
	 
</p>

<p>
	The attackers claimed that to access the documents via a fake service called LawConnect, you needed to request a one-time access code to “easily access” the documents. When hovering over the button, you can see a legitimate Microsoft login URL; however, the URL is crafted to redirect the user to a phishing website.
</p>

<p>
	 
</p>

<p>
	After answering a few<a href="https://www.neowin.net/news/microsoft-is-finally-ditching-annoying-captchas-for-teams-meetings/" rel="external nofollow"> CAPTCHAs</a>, which were likely deployed to stop security crawlers, the user is routed to a page that instructs them to copy a one-time code and then paste it into a legitimate code entry form from Microsoft. This gives access to the attacker's application, which previously generated the code the user just entered. Essentially, the malicious application now has access to the victim’s account.
</p>

<p>
	 
</p>

<p>
	Kaspersky gives the following recommendations for defending against these types of phishing campaigns:
</p>

<blockquote class="QuoteNewsStyle">
	<ul>
		<li>
			If you did not personally initiate a login request on an external device using the Microsoft Device Authorization Grant, do not approve the authorization request.
		</li>
		<li>
			Never enter an authorization code received via unexpected emails or messages, even if the provided link points directly to an official Microsoft domain.
		</li>
		<li>
			Threat actors frequently leverage open redirects on legitimate domains, appending parameters like redirect_uri, return_url, or next after the question mark (?) to point to a malicious destination. Before clicking any link, hover your cursor over it to inspect both the primary domain and any suspicious redirect parameters. Once the page loads, verify that the final URL actually matches the expected asset — this is the absolute minimum requirement before entering corporate credentials.
		</li>
	</ul>
</blockquote>

<p>
	The company also recommends that businesses evaluate if they need Device Code Flow within their corporate infrastructure. It should be disabled globally via the Conditional Access policies within <a href="https://www.neowin.net/news/microsoft-is-making-a-major-change-to-entra-id-authentication/" rel="external nofollow">Microsoft Entra ID</a> if it isn’t absolutely needed. It also said that security teams can set up dedicated monitoring for DeviceCodeSignIn events and that they should strictly enforce device compliance states. Configuring alerts for anomalous sign-in behavior originating from unusual locations is also recommended.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/be-careful-entering-one-time-codes-in-microsofts-login-flow-you-could-be-getting-phished/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 7 July 2026 at 8:31 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35676</guid><pubDate>Mon, 06 Jul 2026 22:31:54 +0000</pubDate></item><item><title>Opera launches Paste Protect, a tool that protects your clipboard from attacks</title><link>https://nsaneforums.com/news/security-privacy-news/opera-launches-paste-protect-a-tool-that-protects-your-clipboard-from-attacks-r35643/</link><description><![CDATA[<h3>
	Opera launches Paste Protect, a built-in tool that blocks malicious actors from accessing your PCs clipboard.
</h3>

<p>
	Popular browser Opera has just launched a feature that protects your clipboard from malicious actors. The feature is called Paste Protect, and it’s built directly into the desktop version of the browser, so there’s no need to configure or turn on anything manually.
</p>

<p>
	 
</p>

<p>
	And indeed, your PC’s clipboard is an underrated but also vulnerable place. The feature is aimed squarely at ClickFix, a social engineering technique that's been spreading fast. It usually starts with a fake error message, a broken CAPTCHA, or a video that won't play, and tricks the victim into copying a command and pasting it into their own terminal or Windows Run dialog.
</p>

<p>
	 
</p>

<p>
	An infiltrated command can then install malware, steal saved credentials, or hand an attacker remote access to your PC. We’ve recently heard of <a href="https://www.neowin.net/news/microsoft-over-394000-windows-pcs-infected-by-lumma-malware-affects-chrome-edge-firefox/" rel="external nofollow">the Lumma Stealer case</a>, which is one of the most widespread infostealers Microsoft has tracked. It used fake CAPTCHAs and ClickFix-style prompts as one of its primary distribution methods. Once inside a system, it went after browser passwords, cryptocurrency wallets, and saved login sessions. Lumma Stealer affected hundreds of thousands of Windows PCs in just two months.
</p>

<p>
	 
</p>

<p>
	Paste Protect is made up of two parts. The first is Hijack protection, a feature Opera has actually had since 2021, which stops external apps from sneakily swapping out something you copied. The second and genuinely new piece is Injection protection. This feature watches your clipboard in real time and, if something suspicious is caught, blocks the access immediately. You’ll then get a warning popup, with a red icon appearing in the address bar.
</p>

<figure class="image image--expandable">
	<img alt="Opera Paste Protect" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/07/1782938389_paste_protect_popup_ui_2.webp">
	<figcaption>
		<em>Image: Opera</em>
	</figcaption>
</figure>

<p>
	Another genuinely useful trait of Paste Protect is that users can peek at the first 120 characters of whatever got blocked. Developers can also whitelist specific sites or force a copy by holding Ctrl+C for five seconds. But we only recommend this if you’re absolutely sure what you’re copying.
</p>

<p>
	 
</p>

<p>
	Opera says its browser is the first major browser to have such a feature, and it checks. Right now, you can only install similar protection in other browsers through various plugin and third-party extensions.
</p>

<p>
	 
</p>

<p>
	You can <a href="https://www.opera.com/opera" rel="external nofollow">download Opera from the official website</a>. The browser is available on Windows, macOS, Linux, ChromeOS, iOS, and Android. But keep in mind that Paste Protect is currently only available on desktop.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/opera-launches-paste-protect-a-tool-that-protects-your-clipboard-from-attacks/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>
<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedauthorid="113165" data-embedcontent="" data-embedid="embed1196150180" src="https://nsaneforums.com/topic/486411-opera-1330593220/?do=embed&amp;comment=1904173&amp;embedComment=1904173&amp;embedDo=findComment#comment-1904173" style="overflow: hidden; height: 334px; max-width: 502px;"></iframe>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 3 July 2026 at 1:08 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35643</guid><pubDate>Fri, 03 Jul 2026 03:10:58 +0000</pubDate></item><item><title>Google Chrome fails users again by letting malicious Perplexity extension slip through</title><link>https://nsaneforums.com/news/security-privacy-news/google-chrome-fails-users-again-by-letting-malicious-perplexity-extension-slip-through-r35634/</link><description><![CDATA[<h3>
	Google has failed users again after it let a malicious Perplexity extension into the Chrome Web Store. It's gone now but a manual uninstall is needed.
</h3>

<p>
	If you have Perplexity AI installed in Google Chrome as an extension, then you need to double-check that it’s the official app and not one of the third-party apps. The reason is that Microsoft’s Defender Security Research Team has found that one of these extensions, called “Search for perplexity ai” is actually malware and secretly records what users are typing. While this discovery led to the extension's removal from the Chrome Web Store, users who installed it are still at risk.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/" rel="external nofollow">According to Microsoft</a>, the extension sends your traffic through a typosquatted domain rather than the legitimate <a href="http://perplexity.ai" rel="external nofollow">perplexity.ai</a>. Upon install, it also requested the chrome_settings_overrides permission to allow it to become your default search engine, ensuring it captured everything you search for in the URL bar.
</p>

<p>
	 
</p>

<p>
	Additionally, it also got permission for declarativeNetRequest, which allowed it to send off your requests to its dodgy server, which the attackers controlled. The permission also allowed the extension to perform traffic redirection and URL rewriting. The extension didn’t need this permission.
</p>

<p>
	 
</p>

<p>
	Here is what Microsoft says the extension does:
</p>

<blockquote class="QuoteNewsStyle">
	<ol>
		<li>
			User enters search query into the Omnibox.
		</li>
		<li>
			Browser request routed to perplexity-ai[.]online.
		</li>
		<li>
			Server logs full request: query string, HTTP headers, user-agent, and source IP address.
		</li>
		<li>
			suggest_url captures real-time keystrokes during typing (before Enter is pressed)
		</li>
		<li>
			Ruleset executes redirect.
		</li>
		<li>
			User is delivered to selected search provider.
		</li>
	</ol>
</blockquote>

<p>
	Another thing that gave away the extension as being malicious was that it shipped with its own server-side infrastructure code, which gave away the entire attack architecture. What we still don’t know is who the operator of this extension and malicious domain is. Microsoft didn’t share this information.
</p>

<p>
	 
</p>

<p>
	To check whether you have this installed, go to <strong>chrome://extensions/</strong> and enable <strong>Developer mode</strong>. If you see a Perplexity extension, check the ID. If it’s “flkebkiofojicogddingbdmcmkpbplcd”, then you need to remove it as it is malicious. While you’re on this page, please remove any other extensions that you do not need. As we have seen, Google isn’t great at screening extensions that appear on the Chrome Web Store, and plenty of malware appears, so if you don’t need or trust extensions explicitly, then they shouldn’t be on your system.
</p>

<p>
	 
</p>

<p>
	Via: <a href="https://www.malwarebytes.com/blog/privacy/2026/07/fake-perplexity-chrome-extension-spies-on-your-searches" rel="external nofollow">Malwarebytes</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/google-chrome-fails-users-again-by-letting-malicious-perplexity-extension-slip-through/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 2 July 2026 at 12:12 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35634</guid><pubDate>Thu, 02 Jul 2026 02:13:03 +0000</pubDate></item><item><title>A critical exploit bypasses Microsoft Defender in Windows 11 and Windows 10 &#x2014; so much for "everyday risk protection without additional software"</title><link>https://nsaneforums.com/news/security-privacy-news/a-critical-exploit-bypasses-microsoft-defender-in-windows-11-and-windows-10-%E2%80%94-so-much-for-everyday-risk-protection-without-additional-software-r35614/</link><description><![CDATA[<h3>
	RoguePlanet flaw in Windows Defender gives hackers full control of Windows 10 and Windows 11 devices.
</h3>

<p id="elk-2b6becaa-a331-41e2-875f-fbd27086e1fc">
	Last month, security researcher <a data-analytics-id="inline-link" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://deadeclipse666.blogspot.com/" href="https://deadeclipse666.blogspot.com/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">Chaotic Eclipse</a> (better known as Nightmare-Eclipse) managed to <strong>bypass Windows 11's sophisticated BitLocker</strong> security feature using a USB stick. Nightmare claimed that :
</p>

<p>
	 
</p>

<p>
	<em>"Could have made some insane cash selling this, but no amount of money will stand between me and my determination against Microsoft." </em>The company has since patched three zero-day exploits published by the security researcher, including YellowKey, GreenPlasma, and MiniPlasma.
</p>

<p>
	 
</p>

<p>
	<a id="elk-seasonal" rel=""></a>
</p>

<p id="elk-2b6becaa-a331-41e2-875f-fbd27086e1fc-2">
	More recently, Nightmare-Eclipse disclosed a new zero-day vulnerability dubbed <strong>RoguePlanet</strong>, which affects Microsoft Defender on both Windows 11 and Windows 10. The exploit could allow attackers to gain full control of affected systems (via ).
</p>

<p>
	 
</p>

<p>
	Microsoft acknowledged the vulnerability and indicated that it's tracking the RoguePlanet zero-day exploit under <a data-analytics-id="inline-link" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.cve.org/CVERecord?id=CVE-2026-50656" href="https://www.cve.org/CVERecord?id=CVE-2026-50656" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">CVE-2026-50656</a>. According to the company:
</p>

<p>
	 
</p>

<p>
	<em>"Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available."</em>
</p>

<p>
	 
</p>

<p>
	The security sleuth shared a proof-of-concept exploit in a self-hosted Git repository, further claiming that Microsoft had scrapped its repository hosting exploits on <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/github" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowscentral.com/tag/github" href="https://www.windowscentral.com/tag/github" rel="external nofollow">GitHub</a> and GitLab.
</p>

<figure id="elk-1af050c4-7d06-4204-919d-944aefa672d3">
	<blockquote class="QuoteNewsStyle">
		<p>
			The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others. The PoC for RoguePlanet works regardless if real time protection is on or not.
		</p>

		<p>
			 
		</p>

		<p>
			<em><cite>Nightmare-Eclipse</cite></em>
		</p>
	</blockquote>
</figure>

<p id="elk-0598f195-a19d-4a98-9f76-2f7912924eed">
	Perhaps more interestingly, this news comes after <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-built-in-defender-antivirus-is-usually-sufficient-for-most-pc-users" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-built-in-defender-antivirus-is-usually-sufficient-for-most-pc-users" href="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-built-in-defender-antivirus-is-usually-sufficient-for-most-pc-users" rel="external nofollow">Microsoft previously fronted Windows 11’s Defender as enough for most PC owners</a>. <em>"Microsoft Defender Antivirus covers everyday risks without requiring additional software,” the company added.</em>
</p>

<p>
	 
</p>

<p>
	The statement seemed highly debatable in the community, though many still agreed with Microsoft's sentiments, including some of Windows Central's readers:
</p>

<p>
	 
</p>

<p>
	<em>"It's not a secret, Windows Defender has been the best or near the best antivirus for years by now. Times when third-party antivirus actually served a purpose are long gone. You're just slowing down your system and paying for no reason."</em>
</p>

<p>
	 
</p>

<p>
	In a subsequent blog post, Microsoft admitted that while Windows 11's Defender is usually enough for most users, <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-defender-is-enough-for-most-users" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-defender-is-enough-for-most-users" href="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-defender-is-enough-for-most-users" rel="external nofollow">third‑party tools add extra layers of protection</a>, including <em>identity monitoring or built-in VPNs.</em>
</p>

<p>
	 
</p>

<p>
	Elsewhere, Nightmare-Eclipse and Microsoft had been locked in a months-long battle, with Microsoft even threatening <strong>legal action</strong>. But after backlash from the wider cybersecurity community, who conduct or publish their findings.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.windowscentral.com/microsoft/a-critical-exploit-bypasses-microsoft-defender-in-windows" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 1 July 2026 at 8:11 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35614</guid><pubDate>Tue, 30 Jun 2026 22:12:10 +0000</pubDate></item><item><title>Can anybody message you on WhatsApp if they know your username?</title><link>https://nsaneforums.com/news/security-privacy-news/can-anybody-message-you-on-whatsapp-if-they-know-your-username-r35613/</link><description><![CDATA[<h3>
	Once you reserve your WhatsApp username, anyone who knows or guesses it can message you; unless you lock it down with a key.
</h3>

<p>
	WhatsApp shook up the community when it began rolling out <a href="https://www.neowin.net/news/whatsapp-is-getting-usernames-and-you-can-reserve-your-preferred-one-now/" rel="external nofollow">usernames yesterday</a>. Username reservations started this week, and full messaging support is coming later in 2026. Once active, you'll be able to give someone your username instead of your number, and they'll be able to message you using that handle alone.
</p>

<figure class="image image--expandable">
	<img alt="WhatsApp username" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782830543_whatsapp_username.webp">
	<figcaption>
		<em>Image: WhatsApp</em>
	</figcaption>
</figure>

<p>
	WhatsApp cites privacy as one of the main reasons for introducing usernames. And on paper, it makes sense. People may be more comfortable with sharing usernames instead of their actual phone numbers. But at the same time, guessing a username is often easier than guessing a full phone number, which raises the question of how reliable usernames are as a security measure.
</p>

<p>
	 
</p>

<p>
	Apparently, that’s the exact thought that a lot of people have been sitting with over the past 24 hours. If usernames replace phone numbers as the way strangers reach you, can anybody who knows your username just message you out of nowhere?
</p>

<h3>
	Can anyone message you on WhatsApp if they know your username?
</h3>

<p>
	To put it simply, yes. If someone has your exact username, they can message you with it, the same way anyone with your phone number can message you today. This is especially risky if you’re reusing the same handle across multiple social media platforms. If your username is similar across your entire digital footprint, it might not be too hard for anyone who might be interested to guess your WhatsApp username.
</p>

<p>
	 
</p>

<p>
	WhatsApp has <a href="https://faq.whatsapp.com/658755553162769/?cms_platform=web" rel="external nofollow">acknowledged </a>this directly, and the company is advising people to avoid using their real name or any handle they already use elsewhere. On top of that, there's no public directory and no search suggestions, so people can't browse for your username the way they can on Instagram or X.
</p>

<p>
	 
</p>

<p>
	WhatsApp has also implemented one additional security measure to prevent spammers or any other unwanted senders from messaging you. So, once you pick your WhatsApp username, it’s highly recommended you enable this option too, just for peace of mind.
</p>

<h3>
	How to lock your WhatsApp username down with a key
</h3>

<p>
	WhatsApp's answer to messages from unwanted senders is an optional username key. This is essentially a secret code attached to your username. Anyone messaging you for the first time through your username will need to enter that key correctly, on top of knowing the username itself. Without it, the conversation won't go through.
</p>

<p>
	 
</p>

<p>
	To enable the username key, head to <strong>Settings </strong>&gt; <strong>Account </strong>&gt; <strong>Username</strong>, the same place you set up your username in the first place. From there, you can create, change, or disable the key whenever you want.
</p>

<figure class="image image--expandable">
	<img alt="WhatsApp username key" class="ipsImage" height="540" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782830397_whatsapp_username_key.webp">
	<figcaption>
		<em>Image: WhatsApp</em>
	</figcaption>
</figure>

<p>
	Even though an additional security measure is definitely good, this still doesn’t feel like the cleanest solution. Because someone who’s messaging you for the first time should remember both your username and the key, which might feel overwhelming.
</p>

<p>
	 
</p>

<p>
	On the other hand, if you'd rather avoid the whole issue, usernames are entirely optional. You can keep using WhatsApp exactly as you do now and skip setting one up altogether.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/reports/can-anybody-message-you-on-whatsapp-if-they-know-your-username/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 1 July 2026 at 8:08 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35613</guid><pubDate>Tue, 30 Jun 2026 22:10:35 +0000</pubDate></item><item><title>CISA: Windows BlueHammer flaw now exploited by ransomware gangs</title><link>https://nsaneforums.com/news/security-privacy-news/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs-r35609/</link><description><![CDATA[<p>
	CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.
</p>

<p>
	 
</p>

<p>
	Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.
</p>

<p>
	 
</p>

<p>
	"Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally," Microsoft explains in a security advisory.
</p>

<p>
	 
</p>

<p>
	Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.
</p>

<p>
	 
</p>

<p>
	With this access, they can escalate to SYSTEM privileges and potentially take complete control of the targeted system.
</p>

<p>
	 
</p>

<p>
	“At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell,” Dormann said.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="demo.jpg" class="ipsImage" data-ratio="75.10" height="540" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2026/April/demo.jpg" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>Exploit demo (Will Dormann)</em></span>
</p>

<p>
	 
</p>

<p>
	Microsoft patched the vulnerability on April 14 as part of the April 2026 Patch Tuesday. However, days later, Huntress Labs security researchers revealed that threat actors had been exploiting it as a zero-day in attacks that showed evidence of "hands-on-keyboard threat actor activity."
</p>

<p>
	 
</p>

<p>
	Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the RoguePlanet, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend flaws.
</p>

<p>
	 
</p>

<p>
	Some of these vulnerabilities affect Microsoft Defender, while others target BitLocker and Windows components.
</p>

<p>
	 
</p>

<p>
	Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey security flaws three weeks ago as part of the June 2026 Patch Tuesday updates.
</p>

<p>
	<br />
	<strong><span style="font-size:22px;">Flagged as exploited by ransomware gangs</span></strong>
</p>

<p>
	 
</p>

<p>
	CISA added the BlueHammer flaw to its Known Exploited Vulnerabilities (KEV) Catalog on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
</p>

<p>
	 
</p>

<p>
	"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the U.S. cybersecurity agency warned at the time.
</p>

<p>
	While Microsoft has yet to tag this security flaw as exploited in attacks, CISA has now also flagged it as exploited in ransomware campaigns in a Monday update to its KEV Catalog.
</p>

<p>
	In recent years, CISA has flagged eight Microsoft Defender vulnerabilities that have been exploited in attacks, with two of them also targeted by ransomware gangs.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">35609</guid><pubDate>Tue, 30 Jun 2026 12:38:49 +0000</pubDate></item><item><title>Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change</title><link>https://nsaneforums.com/news/security-privacy-news/top-google-security-staff-warn-search-data-could-be-hacked-if-eu-rules-change-r35606/</link><description><![CDATA[<p>
	<span><strong>Europe’s pro-competition proposals could see Google Search and Android systems opened up. The company claims there are serious privacy flaws.</strong></span>
</p>

<p>
	 
</p>

<p>
	Google’s top privacy and security staff have warned that plans in Europe, designed to get it to open up its search data and Android operating system to competitors, could lead to people’s search queries being hacked and an increase in cybercrime across the content, according to multiple interviews and documents shared with WIRED.
</p>

<p>
	 
</p>

<p>
	Mountain View’s alarm comes as European Commission officials are set to make final decisions next month in two cases, around Google Search and Android interoperability, under the European Union’s landmark Digital Markets Act competition rules. The rules, which were first adopted at the end of 2022, are designed to force open Big Tech companies that dominate markets, make it easier for others to compete, and reduce reliance on a handful of firms.
</p>

<p>
	 
</p>

<p>
	Heather Adkins, Google’s vice president of security engineering and a founding member of its security team, says the company has concerns around the proposed changes for both Search and Android. In April, the European Commission published initial details, plus now-closed public consultations, on how Google should open up its search data—sharing anonymized search data with rivals—and allowing other AI services to have more access to the Android operating system.
</p>

<p>
	 
</p>

<p>
	“If implemented as described today, I think within a short period of time on Android, we’d see a significant increase in fraud in the EU,” Adkins tells WIRED. “The fraudsters are creative and informed. Past implementation [date], I would give it maybe weeks before we began to see an increase in fraud in Europe.”
</p>

<p>
	 
</p>

<p>
	Meanwhile, Adkins also claims the proposed changes to Google Search could result in people’s search queries being de-anonymized by bad actors and search data shared with small companies being a target for criminal hackers.
</p>

<p>
	 
</p>

<p>
	The European Commission’s proposals are complex, impact technical systems with billions of users, and are steeped in the continent’s competition laws. As European officials’ deadline of July 27 for announcing its final decisions approaches, Google has been increasingly vocal in its opposition to the parts of the plans it does not believe will work. Some Google competitors, who could benefit from accessing the data, say the plans have less privacy and security impacts than has been suggested.
</p>

<p>
	 
</p>

<p>
	These competitors, independent researchers, and academics who have responded to the consultations have pointed out how Europe’s plans could work and also potential flaws with them. Rebuttals and counter rebuttals have been issued as competition law collides with privacy impacts. Spokespeople for the European Commission acknowledged WIRED’s request for comment but did not respond to questions about Google’s concerns.
</p>

<p>
	 
</p>

<p>
	Since the end of 2022, the Digital Markets Act has allowed European officials to designate tech companies that have large market shares as “gatekeepers” and use the rules to get them to open up their systems and data to competitors. Google parent company Alphabet, Amazon, Apple, Booking, ByteDance, Meta, and Microsoft are all considered gatekeepers, with their products—from LinkedIn and TikTok to Instagram and YouTube—being subject to the rules.
</p>

<p>
	 
</p>

<p>
	Google’s search business, which is estimated to make up 90 percent of the worldwide search market, is, unsurprisingly, the only search engine that includes the rules. Under the DMA, Google already shares some data with search engine competitors; however, the planned changes alter how this would work.
</p>

<p>
	 
</p>

<p>
	The plans broadly say Google should provide online search engines with access to search data “on par” with the data that Google itself collects, including “any query input” people enter into Google Search plus some other metadata. Put simply: what people type into Google. It will also have to share click data and the ranking results of search queries. “This is a unique data set which only Google has had access to for many, many years, and there’s not a straightforward way for any other competitor to build or obtain access to something similar,” says Alissa Cooper, the executive director of the tech policy research hub the Knight-Georgetown Institute.
</p>

<p>
	 
</p>

<p>
	These sharing requirements, according to the EU’s proposals, are protected by anonymization methods to protect individuals’ search queries being linked back to them. Those measures will be accompanied with contracts between Google and search competitors that it shares data with, broadly saying they cannot try to reidentify users, link the search data with other information, and that information must be shared securely.
</p>

<p>
	 
</p>

<p>
	Google, however, claims in one document seen by WIRED that the proposed anonymization techniques contain “deep weaknesses” and it would have to release search data at “much higher levels of granularity” than it currently does. Google staff say they have proved the data can be reidentified, and if this is the case, “it is not anonymous in the first place.”
</p>

<p>
	 
</p>

<p>
	“Privacy engineers have proved that this data can be easily reidentified. If data can be reidentified, it is not anonymous in the first place. And the law specifically requires it to be anonymized,” says David Lewis, Google’s director of the company’s privacy advisory for Europe, the Middle East, and Africa. “Whether Google has a vested interest or not is irrelevant to the question of whether millions of people's most private questions may end up with someone they don't know and never expected would see their searches.”
</p>

<p>
	 
</p>

<p>
	The company previously said, according to Reuters’ reporting, that its security red team could reidentify search users based on the data in “less than two hours.” The specific details of those tests have not been published.
</p>

<p>
	 
</p>

<p>
	“Anonymization is hard, and you’ve got to have the right technical experts at the table to come up with the solutions,” says Google’s Adkins, who suggests there is a “middle ground” to be found. Adkins says large language models could also be an “ideal tool” for helping to de-anonymize data if it falls into malicious hands and adds that the company’s threat modeling also includes the data its shares being a target for hackers.
</p>

<p>
	 
</p>

<p>
	“Our working assumption is, if we are asked to hand over data we lose control of it, and we just have no functional execution capability to secure it once it’s beyond the border of what we control,” Adkins says of the contractual approach outlined in the plans. “If you’re a small European startup and you’re getting this data from Google, you’re going to get hacked, and that’s just the kind of reality of the situation,” Adkins claims. The proposals include requirements on companies receiving search data to undergo independent audits of their setups and how data will be securely stored.
</p>

<p>
	 
</p>

<p>
	Europe’s search proposals, plus Google’s response to them, have seen mixed and divisive views from privacy advocates, academics, and lawyers since they were released for public consideration in recent months. Independent security expert Lukasz Olejnik wrote in a long blog post discussing possible risks that the “sanitization” measures around the data “are not adequate for this volume, scale, and privacy landscape.”
</p>

<p>
	 
</p>

<p>
	The risks of reidentification of people’s search queries should be “evaluated” against the proposed protection systems around the data sharing, Lena Hornkohl, an assistant professor of European law at the University of Vienna, has written. Privacy-focused search engine Brave previously told Tech Radar it does not believe the current proposals would result in anonymous data and that they create a “severe privacy risk”—although it said the European Commission should take other measures to limit Google’s dominance instead. Other competitors believe Google’s concerns are unfounded.
</p>

<p>
	 
</p>

<p>
	“The legal standard here doesn’t require eliminating every theoretical risk of reidentification—it requires reducing it to an insignificant level, which the Commission's approach does,” suggests Kamyl Bazbaz, chief communications and policy officer at the privacy-focused search engine DuckDuckGo. “The concerns Google raises are addressable inside the existing framework.”<strong><a href="https://www.wired.com/story/top-google-security-staff-warn-search-data-could-be-hacked-thanks-to-eu-plans/" rel="external nofollow">https://www.wired.com/story/top-google-security-staff-warn-search-data-could-be-hacked-thanks-to-eu-plans/</a></strong>
</p>

<p>
	 
</p>

<p>
	Cooper, from the Knight-Georgetown Institute, says the technical and contractual proposals put forward by the Commission appear to be a “very robust regime” and the data types that would be shared could “unlock” more competition in search. However, she says the answers to privacy and security questions around anonymization and various risks are “knowable” as Google already has the data. “We propose that independent experts have access to the data and be able to validate the properties that the data-sharing is supposed to have,” Cooper says.
</p>

<p>
	 
</p>

<p>
	Away from search, the EU’s proposals for Android could see Google have to further open up the operating system to allow AI firms and agents to use “wake words” on phones and tablets, as well as potentially allowing AI services from other companies to interact with installed applications and data. “I think we have the same goals in mind,” Eugene Liderman, the director of Google’s Android security team, tells WIRED, adding that speedily implementing the plans could create more risks. “It’s just that we have different opinions on how to get there and the pace at how we get there.”
</p>

<p>
	 
</p>

<p>
	Both Liderman and Adkins say Google is concerned that scammers and fraudsters could exploit greater access to apps’ permissions under the proposals. Liderman says providing extra access to microphones, cameras, and onscreen information permissions would undermine mobile security best practices. Apple has, in a rare move, also supported some of Google’s position on operating system access. “We need to put the proper tools in place both from an OS perspective but also from a transparency and accreditation perspective,” Liderman says.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/top-google-security-staff-warn-search-data-could-be-hacked-thanks-to-eu-plans/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">35606</guid><pubDate>Tue, 30 Jun 2026 12:08:12 +0000</pubDate></item><item><title>Google's new hand-wave reCAPTCHA can be bypassed with a stock photo</title><link>https://nsaneforums.com/news/security-privacy-news/googles-new-hand-wave-recaptcha-can-be-bypassed-with-a-stock-photo-r35599/</link><description><![CDATA[<h3>
	Google's new reCAPTCHA method that asks users to record a hand-waving gesture can be bypassed with a stock photo and OBS virtual camera.
</h3>

<figure class="image image--expandable">
	<img alt="Google hand-gesture reCAPTCHA" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782730996_google_recaptcha.webp">
	<figcaption>
		Image: Screenshot
	</figcaption>
</figure>

<p>
	Google is testing a new reCAPTCHA method that asks you to wave at your camera to prove you're human. So, besides solving puzzles and reading distorted text, you can now use your computer’s camera to pass the verification test.
</p>

<p>
	 
</p>

<p>
	When the hand gesture verification is triggered, your browser asks for camera access and prompts you to perform a simple gesture, like a wave or an open palm. Google says it records a short video of the movement and uses AI to extract 21 hand-knuckle coordinates to complete the verification process. The video is then immediately deleted, and Google swears it doesn't keep it.
</p>

<p>
	 
</p>

<p>
	The process alone can be uncomfortable for people who wouldn’t want their biometric data, <a href="https://www.aclu-il.org/campaigns-initiatives/biometric-information-privacy-act-bipa/" rel="external nofollow">which hand scans technically qualify as</a>, recorded. But it gets even more nuanced, as early testers discovered that the new hand-waving reCAPTCHA can be passed with a simple stock image.
</p>

<p>
	 
</p>

<p>
	A user on X tested the new challenge using a stock image of a hand fed through OBS Virtual Camera, and it passed. I wanted to verify it, so I tried the same thing. It took me a few tries and a few stock images, but in the end, I was also able to pass the test. I simply had to readjust the stock image of a generic person waving inside OBS, and Google’s mechanism registered it as a legitimate hand gesture.
</p>

<div data-oembed-url="https://x.com/Patrosi73/status/2071258272389120072">
	<blockquote align="center" class="QuoteNewsStyle" data-dnt="true">
		<p dir="ltr" lang="en">
			BREAKING: google introduces new captcha entirely bypassable using stock images <span class="ipsEmoji">👀</span> <a href="https://t.co/dPWiy5GwTL" rel="external nofollow">https://t.co/dPWiy5GwTL</a> <a href="https://t.co/nMQQPDqIqG" rel="external nofollow">pic.twitter.com/nMQQPDqIqG</a>
		</p>

		<p>
			 
		</p>
		— PatRyk (@Patrosi73) <a href="https://x.com/Patrosi73/status/2071258272389120072?ref_src=twsrc%5Etfw" rel="external nofollow">June 28, 2026</a>
	</blockquote>
</div>

<p>
	Once again, it didn’t even have to be a video or an AI-generated hand animation. Given the simplicity of the process, the entire action can be automated in minutes. All it takes is a simple Python script to render the new reCAPTCHA method obsolete. And it doesn’t even have to be an AI bot, which is usually used for solving puzzles and other verification methods.
</p>

<p>
	 
</p>

<p>
	The <a href="https://docs.cloud.google.com/recaptcha/docs/hand-gesture-verification" rel="external nofollow">new reCAPTCHA method is still in its early phase</a>, and Google will, hopefully, update its AI to at least reject still images. However, this incident, combined with users’ initial<a href="https://www.neowin.net/news/google-launches-gemini-personal-intelligence-to-search-your-drive-and-photos/" rel="external nofollow"> skepticism about Google’s practices regarding user data</a>, likely won’t make too many people wave at the camera anytime soon.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/googles-new-hand-wave-recaptcha-can-be-bypassed-with-a-stock-photo/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 30 June 2026 at 9:00 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35599</guid><pubDate>Mon, 29 Jun 2026 23:01:16 +0000</pubDate></item><item><title>Microsoft Edge gets tons of security features, including AI model that can see your screen</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-edge-gets-tons-of-security-features-including-ai-model-that-can-see-your-screen-r35597/</link><description><![CDATA[<h3>
	Microsoft details new Edge for Business security features, including AI-powered scareware detection, stronger DLP policies, and AI restrictions.
</h3>

<p>
	Microsoft Edge may not be the most popular browser out there, but it does <a href="https://www.neowin.net/news/microsoft-about-to-radically-change-how-often-your-edge-browser-updates/" rel="external nofollow">receive quite frequent updates</a> that <a href="https://www.neowin.net/news/microsoft-will-finally-let-you-sign-in-to-edge-with-a-google-account/" rel="external nofollow">sometimes bring surprising new features</a> and <a href="https://www.neowin.net/news/microsoft-kills-ai-powered-history-search-feature-in-edge/" rel="external nofollow">axe others that are not as popular</a>. Now, Microsoft has detailed some of the new security enhancements that it has introduced in Edge for Business, typically used by commercial customers.
</p>

<p>
	 
</p>

<p>
	Microsoft has emphasized that security features are baked into Edge for Business and offer native integration with security and governance tools like Defender and Purview. Browser sessions are governed by default on managed devices but can also be governed through dedicated work profiles on unmanaged devices.
</p>

<p>
	 
</p>

<p>
	An important aspect in this area is controlling the use of shadow AI. <a href="https://www.neowin.net/news/microsoft-will-allow-it-admins-to-force-copilot-in-edge-over-other-ai-apps/" rel="external nofollow">We have talked about this before</a>, but it essentially restricts employees from using unsanctioned AI apps through data loss prevention (DLP) policies, with Edge redirecting them to trusted AI services like Microsoft 365 Copilot. This feature, available as a pay-as-you-go (PAYG) license, ensures that confidential data never exits AI boundaries set by your organization in Purview.
</p>

<p>
	 
</p>

<figure class="image image--expandable">
	<img alt="Microsoft Edge for Business security features" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782723128_clipboard_image-2-1782405039091.webp">
</figure>

<p>
	Additionally, Microsoft also has strong DLP policies for contractors. Contractors leveraging a Entra ID-joined work profile provisioned by their contracting company on a device managed by their actual employer can be restricted from downloading files locally. In such scenarios, the file is saved on the contracting firm's OneDrive rather than being downloaded locally.
</p>

<p>
	 
</p>

<figure class="image image--expandable">
	<img alt="Microsoft Edge for Business security features" class="ipsImage" height="206" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782723123_clipboard_image-3-1782405039011.webp">
</figure>

<p>
	Another useful Edge security feature disallows copying and pasting from unmanaged locations and apps. Similarly, DLP policies can be configured at a granular level to restrict screenshots or downloading of files from certain locations. In the same vein, IT admins can block the installation of extensions, hosted apps, themes and scripts, and control if users can install extensions from external locations. They can also enable the installation of specific extensions and allow users to request access to certain extensions, so that they can be managed on a case-by-case basis.
</p>

<p>
	 
</p>

<figure class="image image--expandable">
	<img alt="Microsoft Edge for Business security features" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782723117_clipboard_image-4-1782405039045.webp">
</figure>

<p>
	Finally, Edge for Business now has an on-device AI model that uses computer vision to see what's on your screen and block potentially malicious content immediately. This does not rely on site reputation, as it simply monitors what is being displayed on your screen, which means that it is effective against malicious content that takes over your screen and employs scareware tactics. Since this is an on-device AI model, it does use your system's resources, so it's enabled by default only on devices with at least 2GB of RAM and four CPU cores. You can find more details in the Microsoft Mechanics video <a href="https://www.youtube.com/watch?v=F4yO6E1guDc" rel="external nofollow">here</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-edge-gets-tons-of-security-features-including-ai-model-that-can-see-your-screen/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 30 June 2026 at 8:58 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35597</guid><pubDate>Mon, 29 Jun 2026 22:59:19 +0000</pubDate></item><item><title>WhatsApp is getting usernames, and you can reserve your preferred one now</title><link>https://nsaneforums.com/news/security-privacy-news/whatsapp-is-getting-usernames-and-you-can-reserve-your-preferred-one-now-r35596/</link><description><![CDATA[<h3>
	WhatsApp has opened username reservations ahead of a wider rollout, giving users a new way to connect with added privacy.
</h3>

<p>
	 
</p>

<p>
	Sharing your phone number isn't always something you want to do, especially with people you've just met. Whether it's someone from a class, a local community group, or a sports team chat, handing over your number can feel like giving away more personal information than necessary. That's exactly the problem WhatsApp is trying to solve with its upcoming usernames feature.
</p>

<p>
	 
</p>

<p>
	The company has announced that users can now reserve a unique WhatsApp username ahead of the feature's wider rollout later this year. Once usernames become available, they'll let people connect without revealing their phone numbers. It's a change that makes a lot of sense for group chats. Right now, everyone in the group can see your phone number. With usernames enabled, that won't necessarily be the case when someone contacts you for the first time.
</p>

<p>
	 
</p>

<div class="videostyle">
	<video controls="" preload="metadata" data-controller="core.global.core.embeddedvideo">
		<source type="video/mp4" src="https://about.fb.com/wp-content/uploads/2026/06/WhatsApp-Usernames-LaunchFilm.mp4">
	</source></video>
</div>

<p>
	 
</p>

<p>
	WhatsApp says it's opening username reservations early because more than three billion people use the app, meaning plenty of people are likely to want the same usernames. Reserving one now gives users a better chance of securing the name they actually want before the feature launches more broadly. If your preferred username is already taken, WhatsApp will also offer a built-in username generator to suggest available alternatives.
</p>

<p>
	 
</p>

<p>
	The feature isn't only aimed at individual users. Creators, businesses, and organisations will be able to claim the same username they already use on Instagram or Facebook, making it easier to keep a consistent identity across Meta's apps.
</p>

<p>
	 
</p>

<p>
	Furthermore, privacy is a big part of how WhatsApp is introducing usernames. There won't be a public directory where people can browse or search for usernames. Instead, people will need to know your exact username before they can start a conversation with you. Additionally, users can also choose to enable a username key, which adds another layer of control by requiring people to enter that key before sending a message.
</p>

<p>
	 
</p>

<p class="img-center">
	<img alt="WhatsApp Username" class="ipsImage" height="627" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/06/1782756634_whatsapp_usernames.webp">
</p>

<p>
	 
</p>

<p>
	Once <a href="https://about.fb.com/news/2026/06/its-time-to-reserve-your-whatsapp-username/" rel="external nofollow">the feature</a> rolls out, people who choose to use a username will no longer have their phone number shown when messaging a person or business for the first time. If you want to reserve a username, make sure you're running the latest version of WhatsApp, then head to Settings &gt; Account &gt; Username.
</p>

<p>
	 
</p>

<p>
	The tech giant says usernames will roll out gradually over the coming months, and users will receive an in-app notification when the feature becomes available in their country.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/whatsapp-is-getting-usernames-and-you-can-reserve-your-preferred-one-now/?utm_source=rss" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 30 June 2026 at 8:56 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35596</guid><pubDate>Mon, 29 Jun 2026 22:58:18 +0000</pubDate></item><item><title>How People in China Keep Outsmarting Anthropic&#x2019;s Geolocation Restrictions</title><link>https://nsaneforums.com/news/security-privacy-news/how-people-in-china-keep-outsmarting-anthropic%E2%80%99s-geolocation-restrictions-r35579/</link><description><![CDATA[<p>
	<span style="color:#c0392b;"><span style="font-size:16px;"><strong>As Anthropic tightens restrictions on access to Claude in China, users keep finding new workarounds, from proxy services to fake identities sourced on Telegram.</strong></span></span>
</p>

<p>
	 
</p>

<p>
	<strong>Anthropic goes to </strong>great lengths to prevent people in China from using its AI models, but in practice, its safeguards have often failed. Over the past year, startups, researchers, and tech enthusiasts across the country have developed increasingly sophisticated workarounds to access Claude. Many of them consider it the world’s most capable AI assistant, making the extra effort to obtain it worthwhile.
</p>

<p>
	 
</p>

<p>
	In early June, Anthropic publicly released Fable 5, a safeguarded version of its most powerful AI model to date, Mythos. Chinese social media immediately lit up with posts from people sharing their impressions after trying it out. (Anthropic revoked access to the model worldwide a few days later in response to export controls imposed by the Trump administration).
</p>

<p>
	 
</p>

<p>
	Chinese people generally can access other Western AI tools, such as OpenAI’s ChatGPT, by using virtual private networks, foreign phone numbers, and international payment methods to create and maintain their accounts. But Anthropic has arguably taken more aggressive steps, such as banning accounts that it suspects are owned and controlled by people located in China. On Chinese social media, users frequently report that they have been suspended from Claude without warning, despite taking those precautions.
</p>

<p>
	 
</p>

<p>
	The cat-and-mouse game has fueled a thriving underground economy for Claude access in China. Accounts are sold on Chinese ecommerce platforms like Taobao and through illicit marketplaces on Telegram. More recently, a cottage industry of “transfer stations” has also emerged. These services act as intermediaries, purchasing access to Anthropic’s API outside China and then redistributing Claude API tokens to users inside the country. The set up is designed to give startups and other professional users more stable and reliable access to AI assistant.
</p>

<p>
	 
</p>

<p>
	Michael Aciman, a spokesperson for Anthropic, says that the company uses a range of evolving detection systems, including identity verification, to enforce its policies against unauthorized access to Claude. He added that Anthropic has also worked to detect and disrupt proxy networks used to provide access to the chatbot in China.
</p>

<p>
	 
</p>

<p>
	Despite all of the difficulties Chinese people are forced to overcome to use Claude, there remain many loyal fans of Anthropic in the country. It’s especially popular among programmers. Even though Chinese companies like DeepSeek and Z.ai have some of the most capable open-source large language models on the market, third-party tests still show that they lag behind leading closed models like Claude. During a recent reporting trip to China, WIRED spoke to academics and engineers at multiple tech companies who said that they preferred using Claude over Chinese models to generate code, and are eager to try out each new model that Anthropic releases.
</p>

<p>
	 
</p>

<p>
	Zilan Qian, a research associate at the Oxford China Policy Lab, looked into the black market for reselling Western AI tokens to Chinese users. He noted that Chinese software developers say they overwhelmingly prefer using tools like Claude Code and OpenAI’s Codex compared to tools from domestic companies. “Analysis shows that Chinese models are still six to nine months behind the US models, and for specific things like coding and developing, you can obviously tell the gap,” Qian says.
</p>

<p>
	 
</p>

<p>
	“For both Chinese AI policymakers and technical people, they have much less of a problem drawing on and using American ideas or products, regardless of the geopolitical or ideological rivalry,” says Matt Sheehan, a senior fellow at the Carnegie Endowment for International Peace, where he researches AI policy and China. “It’s Americans who tend to think an idea or a product is tainted just because it comes from their rival,” he says.
</p>

<p>
	 
</p>

<p>
	Dario Amodei, Anthropic’s cofounder and CEO, often explicitly singles out Chinese access to frontier models as a critical threat to US national security. Just this week, Anthropic accused Alibaba of using Claude outputs to train the Chinese company’s rival models, a technique known as “distillation.” Anthropic has also claimed other Chinese companies have done the same thing in the past. For this and other national security reasons, Anthropic does not offer commercial access to Claude in China, or to subsidiaries of Chinese companies located outside of the country.<br />
	 
</p>

<p>
	Still, people continue to find workarounds. For casual users, that might mean sticking to classic tactics like turning on a VPN and using a consistent proxy location, creating the illusion that they are always connecting to Claude from the same place instead of bouncing around the world. Less technical users can go on Chinese ecommerce platforms like Taobao and Xianyu to buy Claude accounts that have already been set up. Anthropic often still bans them after a while, but for people who only want to briefly test Claude or ask occasional questions, the loss is manageable.
</p>

<p>
	 
</p>

<p>
	Similar marketplaces have popped up on Telegram over the last few years, says Hieu Minh Ngo, a reformed criminal hacker turned cybercrime investigator at the Vietnamese scam-fighting nonprofit ChongLuaDao. On websites and Telegram channels Ngo and other researchers shared with WIRED, users market what they claim to be Claude Pro and Claude Max accounts, alongside others for ChatGPT Plus and Gemini Plus. These underground Chinese-language marketplaces particularly focus on selling “pro” accounts, which allow greater numbers of prompts to be sent, Ngo says.
</p>

<p>
	 
</p>

<p>
	The frenzy over OpenClaw in China earlier this year also fueled demand for AI agents, Qian says. Because these tools perform more complex tasks, they consume far more tokens than a typical chatbot session. For heavy users, especially developers who need a constant stream of prompts and responses, finding affordable, reliable access to tools like Claude and Codex quickly became a necessity.
</p>

<p>
	 
</p>

<p>
	That’s when transfer stations, also called relay stations, came in. Set up with servers in an Anthropic-supported country, they work as middlemen between Chinese users and Anthropic. Instead of logging into Claude directly, a user sends prompts to a locally-accessible website, which forwards the request to Claude through individual accounts or API keys. The response from the model is then passed back to the user. To the user, it can feel the same as chatting with Claude, just on a different platform. To make it more appealing to heavy users, transfer stations often charge a cheaper price than Claude’s own API access since they can get enterprise discounts from Anthropic and other licensed distributors.
</p>

<p>
	 
</p>

<p>
	Today, the demand has spurred Chinese-language websites and GitHub pages listing dozens of transfer stations and comparing a variety of models and token prices. Even the infamous Chinese crypto billionaire Justin Sun joined the game and opened his own transfer station in May.
</p>

<p>
	 
</p>

<p>
	The sheer number of Chinese users accessing Anthropic through proxy connections may have distorted the picture of who’s using Claude worldwide. Singapore, with its prominence in international business and dominant use of the Chinese language, often becomes the prime target for Chinese users to fake their geographic locations or route through transfer station traffic. Anthropic’s published data says that Singapore, a country of merely 6 million people, is often among the top countries in the world by Claude adoption relative to population size (the United States still uses Claude far more than any other country, according to the data).
</p>

<p>
	 
</p>

<p>
	Anthropic has continued tightening its restrictions to keep people in China and other restricted countries out. In April, the company rolled out identity verification for some Claude users. The process is handled by Persona, a third-party company backed by the venture capital fund Founders Fund, which requires users to upload a government-issued photo ID, such as a passport, driver’s license, or national identity card before they can log into Claude. IDs from unsupported countries won’t count. And if an account fails to pass the verification test, it could be banned.
</p>

<p>
	 
</p>

<p>
	The requirement, which some Chinese users have compared to the Know Your Customer (KYC) identity verification required by financial institutions, shifted the workaround market away from Claude accounts and APIs and toward fake identities. Over the past couple of months, Ngo says he has seen Chinese-language Telegram channels begin advertising Claude accounts that have already passed the identification checks. “They are talking about how to bypass KYC, where to buy the Claude KYC so they can use it,” Ngo says.
</p>

<p>
	 
</p>

<p>
	Perhaps it’s time to acknowledge that, no matter how strictly Anthropic enforces its geographical restrictions, as long as models are still released to the general public, savvy users in China and other unsupported countries will likely continue to find ways to keep using Claude. And the black markets are always ready to provide non-technical users with turnkey solutions.
</p>

<p>
	 
</p>

<p>
	But the unfortunate result is that by accessing Claude through more and more unsanctioned tools, users are also exposing themselves to more security risks. Not only can they be scammed by sellers on Telegram, the sensitive information and prompts they send through transfer stations could end up being packaged and sold by the intermediary company to unscrupulous buyers. All of these added wrinkles will pose new challenges for AI safety. “People who are working on AI safety need to think, if this transfer station infrastructure remains, how are you going to monitor bad actors and prevent them from doing bad things?” Qian says.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/how-people-in-china-keep-outsmarting-anthropics-geolocation-restrictions/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">35579</guid><pubDate>Sun, 28 Jun 2026 19:59:57 +0000</pubDate></item><item><title>Here&#x2019;s How to Opt Out of Google Search&#x2019;s New AI Data Training Feature</title><link>https://nsaneforums.com/news/security-privacy-news/here%E2%80%99s-how-to-opt-out-of-google-search%E2%80%99s-new-ai-data-training-feature-r35578/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>Google’s Search history update stores media uploads from your interactions, like images used in reverse image searches, for training its AI models.</strong></span>
</p>

<p>
	 
</p>

<p>
	<strong>A little piece</strong> of my soul shrivels up every time I get a message laying out how another company plans to use personal data in ever encroaching ways for AI training. I got one of those emails recently from Google, with the subject line: “New privacy settings for Search services.” It’s part of Google’s global rollout happening over the next few months that will change how it handles users' Search history data.
</p>

<p>
	 
</p>

<p>
	Every piece of media, from photos you upload for reverse image searches to audio of you speaking with Google Translate, may be retained in your account and used to improve Google’s AI models.
</p>

<p>
	This new option in Google’s account settings, called Search Services History, was already enabled when I visited the page for the first time. (If a user previously disabled Google’s Web &amp; App Activity and Search Personalization toggles, then it would be off.) Also, the box to save all my uploaded media from Google Search for AI training was already checked. Great.
</p>

<p>
	 
</p>

<p>
	When this rolls out to your account, you can visit Google’s My Activity page and then select the Search Services History tab to opt out. This page gives you a solid sense of what Google saves from your Search history. It’s also where you can turn off the entire setting and delete your activity. It’s critical to uncheck the box next to Save media if you don’t want your image uploads used for AI training.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="Screenshot%202026-06-23%20at%2011.10.43%" class="ipsImage" data-ratio="75.10" height="540" width="620" src="https://media.wired.com/photos/6a3b33fc0e81c1ff23a77f9e/master/w_1600,c_limit/Screenshot%202026-06-23%20at%2011.10.43%E2%80%AFAM.png" />
</p>

<p style="text-align:center;">
	<em><span style="font-size:12px;">Courtesy of Reece Rogers</span></em>
</p>

<p>
	 
</p>

<p>
	It’s worth doing this change now rather than later. There’s not much you can do after your media data is thrown into the AI blender. “If your saved media is used to train our AI models, it is disconnected from your Google Account. This training data will be kept for up to 4 years, even if you delete the original activity,” read the pop-up when I turned off this feature. That’s such a long time for my random image Search uploads to float around in the digital ether.
</p>

<p>
	 
</p>

<p>
	“These new settings help users get more relevant results and revisit their searches—including visual and voice searches—and they can be turned on or off at any time,” says Davis Thompson, a Google spokesperson, over email when reached for comment. He did not answer WIRED’s question about this feature being on by default.
</p>

<p>
	 
</p>

<p>
	What’s really being saved here? Google is clear that it's starting to store much more than just what you type into Search. “Your saved media includes your images, files, and audio and video recordings from your interactions with Search services,” reads the page’s description. “This includes things like Google Lens images, recordings from Search Live or Translate speaking practice, content you upload, and voice searches.”
</p>

<p>
	 
</p>

<p>
	This is because AI models don’t just need text data to improve; they need diverse inputs in other forms, like audio or video. If Google can gather more data, and more types of data, from its vast array of users, then maybe it could innovate faster than its competitors.
</p>

<p>
	 
</p>

<p>
	Google's massive user base is spread across multiple services, giving it an edge in data collection. “Google is in a unique spot compared to a lot of the other companies with this,” says Thorin Klosowski, a senior security and privacy activist at the Electronic Frontier Foundation. “Because they offer so many services that people have been using for so long and have grown pretty comfortable and complacent with the amount of data collected.” Apps that people use every day have a kind of built-in inertia, so changes that users don't like may not be enough to drive them to alternative services.
</p>

<p>
	 
</p>

<p>
	Being forced to opt out of AI training seems to be the standard across sites and platforms. It doesn’t have to be this way. “I think ‘opt in’ is really asking the bare minimum of these companies,” Klosowski says. “Asking their users to consciously choose to enable these features is the least they can do.” Google would have to make a stronger case to users on why these features could be helpful if they weren’t automatically just turned on, Klosowski says.
</p>

<p>
	 
</p>

<p>
	In Google’s email sent to my testing account on June 23, the first sentence framed this change as giving me “even more control over saved history.” Google then provided examples in the message showing how saving this media may be helpful. “For example, this lets you revisit your past visual searches with Lens or continue a Search Live conversation about a song you heard.” In contrast, it’s notable that Google didn’t provide similar examples after stating near the end of the email that this saved media will be used for AI model training. Rather, the message just continued to the next detail.
</p>

<p>
	This is another major software change that is worth slowing down to process the change for everyday users. “It creates this extra layer of math that a consumer has to do about whether they feel comfortable using the tool they've been using for a long time,” says Ben Winters, director of AI and privacy at the Consumer Federation of America.
</p>

<p>
	 
</p>

<p>
	I’m constantly overwhelmed that it's always on me to opt out of data training for every service. It leaves me feeling like a schmuck who’s probably going to miss something buried in all these settings, no matter what.
</p>

<p>
	 
</p>

<p>
	Winters sees this change from Google as placing the onus on users to avoid AI training, which may contribute to widespread user exhaustion bordering on nihilism. “There’s an increasing feeling of powerlessness and hopelessness about even trying to protect your data, because every little thing is going to be squeezed out of you,” he says.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/how-to-opt-out-of-google-search-new-ai-data-training/#intcid=_wired-verso-hp-trending_346e3c3e-bcd1-4c7a-8e9c-e6f39e21e4d7_popular4-2" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">35578</guid><pubDate>Sun, 28 Jun 2026 19:52:08 +0000</pubDate></item><item><title>LastPass Breached Once Again, Hackers Gain Access to Sensitive Customer Data</title><link>https://nsaneforums.com/news/security-privacy-news/lastpass-breached-once-again-hackers-gain-access-to-sensitive-customer-data-r35521/</link><description><![CDATA[<p>
	Though the breached occurred at a third-party service provider, hackers used that access to steal LastPass customers' contact info and physical addresses.
</p>

<div data-parent-group="author-byline" id="author-byline">
	<div>
		 
	</div>

	<div>
		<div>
			<small>(Credit: Mateusz Slodkowski/SOPA Images/LightRocket via Getty Images)</small>
		</div>

		<div>
			<article data-autopogo="" data-parent-group="content-body" id="article">
				<p>
					 
				</p>

				<p>
					Password management app LastPass has<span> </span><a href="https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response" target="_blank" title="(Opens in a new tab)" rel="external nofollow">confirmed</a><span> </span>that sensitive customer data was stolen in a new security incident.
				</p>

				<p>
					 
				</p>

				<p>
					Exposed data includes customers' names, phone numbers, physical addresses, and email addresses. According to LastPass, the breach originated at Klue, a third-party market intelligence service it has integrated with its own systems. Hackers obtained<span> </span><a href="https://www.pcmag.com/encyclopedia/term/oath" target="_self" rel="external nofollow">LastPass OAuth tokens</a> held by Klue and used them to access customer data.
				</p>

				<p>
					 
				</p>

				<p>
					The<span> </span><a href="https://www.pcmag.com/picks/the-best-password-managers" target="_self" rel="external nofollow">password manager</a><span> </span>says it became aware of the incident on June 12 and has since blocked the unauthorized access. “LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure,” it adds.
				</p>

				<p>
					 
				</p>

				<p>
					The latest lapse isn’t as severe as the company’s<span> </span><a href="https://www.pcmag.com/news/lastpass-hack-gets-worse-culprit-stole-customers-encrypted-password-vaults" target="_self" rel="external nofollow">2022 breach</a>, in which a hacker obtained copies of customers’ encrypted passwords. LastPass agreed to settle a lawsuit related to that incident by<span> </span><a href="https://www.pcmag.com/news/affected-by-this-lastpass-breach-how-to-get-a-cut-of-the-245m-settlement" target="_self" rel="external nofollow">paying $24.5 million to affected customers</a><span> </span>earlier this year, and anyone who used the app before November 2022 is eligible to file a claim before July 2, 2026.
				</p>

				<p>
					 
				</p>

				<p>
					Following its latest leak, LastPass has asked customers to remain vigilant for possible<span> </span><a href="https://www.pcmag.com/explainers/how-to-spot-and-avoid-phishing-scams-5-tips-from-our-security-expert" target="_self" rel="external nofollow">phishing</a><span> </span>attempts. "Always exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information," it says. "Please remember that no one at LastPass will ever ask for your master password."
				</p>

				<p>
					 
				</p>

				<p>
					<a href="https://www.pcmag.com/news/lastpass-breached-once-again-hackers-gain-access-to-sensitive-customer" rel="external nofollow">Source</a>
				</p>
			</article>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">35521</guid><pubDate>Wed, 24 Jun 2026 19:24:11 +0000</pubDate></item><item><title>Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack</title><link>https://nsaneforums.com/news/security-privacy-news/apple-and-tesla-trade-secrets-reportedly-exposed-following-a-tata-electronics-cyberattack-r35502/</link><description><![CDATA[<h3>
	Up to 630GB of data was reportedly stolen by hackers, but Tata says its operations have not been impacted.
</h3>

<p>
	Tata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a <a href="https://www.neowin.net/news/foxconn-to-make-iphone-casings-in-india-as-apple-shifts-more-production-from-china/" rel="external nofollow">manufacturing partner of both Apple</a> and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies.
</p>

<p>
	 
</p>

<p>
	The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told <a href="https://www.reuters.com/business/media-telecom/indias-tata-electronics-hit-by-cyber-breach-claiming-expose-apple-tesla-trade-2026-06-22/" rel="external nofollow">Reuters </a>that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.”
</p>

<p>
	 
</p>

<p>
	The ransomware group reportedly sent a ransom demand to Tata Electronics, while Apple has launched an investigation into the incident. World Leaks claims it stole more than 200,000 files totaling over 630GB from Tata Electronics.
</p>

<p>
	 
</p>

<p>
	Some database files on the ransomware group’s website are titled "com.apple.factorydata," which could refer to Apple’s iPhone production operations in India. Moreover, some documents reportedly contain material specifications and quality inspection standards for iPhone circuit board components.
</p>

<p>
	 
</p>

<p>
	However, Apple is not the only affected company. A folder found in the World Leaks database is titled "NV36 Chargeport Controller - North America," which may refer to Tesla Model Y components.
</p>

<p>
	 
</p>

<p>
	Additionally, other files in the database reportedly contain drawings related to Tesla’s Project Highland, the internal codename for the EV maker’s updated Model 3 sedan. To support the authenticity of the stolen files, World Leaks has published documents containing footers that read: "This document contains proprietary and confidential information of Apple Inc." and "information contained herein is deemed confidential, proprietary, and a trade secret of Tesla Inc."
</p>

<p>
	 
</p>

<p>
	Cybersecurity researcher Rajshekhar Rajaharia told Reuters that the database also contains emails, event logs spanning several years, and passport copies of employees, including foreign nationals. Both Tesla and Apple have declined to comment on the scale of the incident.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/apple-and-tesla-trade-secrets-reportedly-exposed-following-a-tata-electronics-cyberattack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 23 June 2026 at 6:24 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35502</guid><pubDate>Tue, 23 Jun 2026 08:25:09 +0000</pubDate></item><item><title>Following user outcry, AMD reinstates memory encryption in consumer CPUs</title><link>https://nsaneforums.com/news/security-privacy-news/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpus-r35498/</link><description><![CDATA[<h3>
	Critics saw the move as an underhanded way to steer them toward more costly chips.
</h3>

<p>
	Consumer AMD CPUs will once again offer encryption protections against physical attacks after facing user backlash for silently removing the feature.
</p>

<p>
	 
</p>

<p>
	As <a href="https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/" rel="external nofollow">Ars reported</a> last week, AMD stripped the protection, known as <a href="link" rel="">TSME</a>, from consumer Ryzen processors. Short for Transparent Secure Memory Encryption, TSME encrypts the entire contents stored in memory, making the data useless to adversaries performing <a href="https://en.wikipedia.org/wiki/Cold_boot_attack" rel="external nofollow">cold boot attacks</a> and similar intrusions requiring physical access.
</p>

<h2>
	Now you see it, now you don’t, soon you’ll see it again
</h2>

<p>
	About a decade ago, AMD added TSME to its high-end CPUs. Over the next few years, AMD added the protection to lower-end processors, including the consumer version of its Ryzen chips, a CPU that costs less than the Pro version. Over the years, users of these lower-end chips have gotten used to the added security, although some security experts (and plenty of novices, too) note that consumer chips are far less likely to be targeted by physical attacks. Recently and without warning or notice, the lower-end line of AMD chips suddenly dropped the protection, and it did so in a way that was impossible to detect on Windows machines and required a fair amount of technical work when using Linux. AMD last week declined to explain or acknowledge the change.
</p>

<p>
	 
</p>

<p>
	Following the revelation, social media was deluged by comments from AMD consumers decrying the move. They noted that AMD’s quiet removal of TSME after supporting it for so long seemed underhanded. The move came solely as a result of firmware changes made in a recent update. With no physical changes required to silicon, continued support was largely, if not purely, a matter of will rather than a necessity required by changes to hardware. The critics called on AMD to reverse the move.
</p>

<p>
	 
</p>

<p>
	Over the weekend, AMD said it planned to do just that in a firmware update scheduled for release next month. More often than not, the chipmaker refers to TSME as Memory Guard.
</p>

<p>
	 
</p>

<p>
	“Regarding certain non-PRO Ryzen 9000-series desktop processors, a BIOS option to enable Memory Guard was previously available but was removed in a recent update,” AMD said in an email. “Based on valuable community feedback, we will reinstate this option in an upcoming BIOS release in July.”
</p>

<p>
	 
</p>

<p>
	The company has yet to explain why it removed the protection. Critics speculate that AMD dropped it in an attempt to steer customers toward more costly CPUs.
</p>

<p>
	 
</p>

<p>
	It’s possible, though, that there were less nefarious reasons, such as the difficulty of continued support as chip designs changed. Another possibility is that AMD made the move for performance reasons. Encrypting and decrypting data in memory creates latency. Slowdowns are the enemy of gamers, one of the more popular customer segments using the 9000-line of Ryzen processors. Since many gamers already voluntarily disabled TSME and had little need for it in the first place, AMD may not have considered the change of much consequence.
</p>

<p>
	 
</p>

<p>
	The incident, and AMD’s refusal to discuss it, is emblematic of the public relations landscape that has emerged over the past two decades. Once, Big Tech and corporations in general were willing to acknowledge service and product changes to ensure customers had a predictable experience. They also showed a willingness to admit mistakes and to say how they planned to do better. Now, there’s only silence. As the companies’ power and dominance have mushroomed, their sense of accountability has diminished proportionately.
</p>

<p>
	 
</p>

<p>
	AMD didn’t respond to questions sent for this story.
</p>

<p>
	 
</p>

<p>
	TSME transparently encrypts all physical memory flowing in or out of the processor. It protects against cold boot attacks and similar attacks that use sophisticated techniques to siphon data out of memory chips once an adversary has gained physical access to them. Memory pages are automatically encrypted and decrypted on each write or read. An ephemeral encryption key is created during each system start and isn’t accessible by software. Unlike Secure Memory Encryption, TSME is OS independent, a condition that makes it much easier to enable.
</p>

<p>
	 
</p>

<p>
	The automatic encryption and decryption does come at a performance cost that differs depending on the tasks the chips are performing. Some game developers advise users to disable TSME.
</p>

<p>
	 
</p>

<p>
	Oftentimes, disabling security protections is frowned upon. In this case, the move is less risky since systems running consumer chips are less likely to store data that’s valuable enough to motivate a sophisticated physical attack.
</p>

<p>
	 
</p>

<p>
	The counterargument is that AMD has included TSME in its consumer Ryzen CPUs for about a decade. The company long left the decision to enable or disable the protection to users. Critics argue that the removal deprived them of a capability that had been tacitly promised. Making the move silently only added to the sense AMD was pulling a fast one.
</p>

<p>
	 
</p>

<p>
	Despite AMD’s continued opacity about the incident, the company deserves credit for restoring TSME. Customers complained, some bitterly, and AMD heard and granted their demands.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/06/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpus/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 23 June 2026 at 11:37 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35498</guid><pubDate>Tue, 23 Jun 2026 01:37:58 +0000</pubDate></item><item><title>AryStinger botnet infected thousands of D-Link routers worldwide</title><link>https://nsaneforums.com/news/security-privacy-news/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide-r35477/</link><description><![CDATA[<p>
	A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.
</p>

<p>
	 
</p>

<p>
	Researchers at Qianxin's XLab threat intelligence team say that the malware converts infected devices into remotely controlled “executors” that can perform scanning, proxying, tunneling, command execution, and other activities on behalf of the attacker.
</p>

<p>
	 
</p>

<p>
	“The attacker can split a massive scanning task into multiple small chunks and distribute them to different Executors for parallel execution,” <a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" rel="external nofollow">XLab researchers note</a>.
</p>

<p>
	 
</p>

<p>
	“With this distributed-like design, the attacker can efficiently complete the early "footprinting" activities, thereby providing strong assurance for the smoothness and success rate of subsequent intrusion operations.”
</p>

<p>
	 
</p>

<p>
	Apart from using compromised routers as a springboard for malicious operations, XLab warns that the malware can also tamper with DNS settings, hijacking the user’s browsing, and silently monitor and potentially steal all inbound and outbound network traffic.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Server distributing AryStinger scan jobs" class="ipsImage" height="294" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2026/June/massprod_scanip.jpg">
		<figcaption>
			<em>Server distributing AryStinger scan jobs<br>
			Source: XLab</em>
		</figcaption>
	</figure>
</div>

<p>
	AryStinger exploits older flaws such as CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, targeting primarily D-Link DIR-850L, D-Link DIR-818LW routers.
</p>

<p>
	 
</p>

<p>
	The two router models were <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10503" rel="external nofollow">previously targeted</a> by the <a href="https://www.bleepingcomputer.com/news/security/avrecon-malware-infects-70-000-linux-routers-to-build-botnet/" rel="external nofollow">AVrecon malware botne</a>t that Lumen communications services provider Lumen disrupted in 2023.
</p>

<p>
	 
</p>

<p>
	Qianxin's telemetry data shows that almost half of all infections are located in South Korea (48.5%), followed by China (31.8%), Sweden (6.4%), Malaysia (3.5%), and Singapore (2.5%).
</p>

<p>
	 
</p>

<p>
	XLab researchers found two variants of the AryStinger malware: a C-based version targeting mostly outdated routers, and a Go-based one that focuses on NAS systems, but currently with a far more limited reach.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Infected router establishing C2 communication" class="ipsImage" height="439" style="height: auto;" width="900" src="https://www.bleepstatic.com/images/news/u/1220909/2026/June/massprod_log.jpg">
		<figcaption>
			<em>Infected router establishing C2 communication<br>
			Source: XLab</em>
		</figcaption>
	</figure>
</div>

<p>
	The NAS version is the most advanced of the two, featuring additional capabilities such as IP and DNS scanning, command execution, payload execution, and internal network reconnaissance through the integration of open-source penetration testing tools.
</p>

<p>
	 
</p>

<p>
	The researchers noted that AryStinger's distributed DNS-scanning infrastructure could potentially be repurposed to generate large volumes of DNS queries against resolvers, although they did not observe any such attacks.
</p>

<p>
	 
</p>

<p>
	Regarding the NAS version's code execution capabilities, XLab says there’s support for Shell commands, as well as Go, Java, and Python source code.
</p>

<p>
	 
</p>

<p>
	However, there are some limitations to using source code instead of compiled binaries, as compilation requires language runtimes on the host, and the process as a whole introduces noise that can break stealth.
</p>

<p>
	 
</p>

<p>
	The researchers did not attribute AryStinger to any known activity cluster, stating that “many mysteries surrounding AryStinger remain to be solved.”
</p>

<p>
	 
</p>

<p>
	Owners of end-of-life (EoL) routers should replace them with new, actively supported models, apply the latest available firmware updates, change the default administrator account password, and disable remote management panels.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Monday 22 June 2026 at 7:39 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35477</guid><pubDate>Sun, 21 Jun 2026 21:40:19 +0000</pubDate></item><item><title>Microsoft discovers new lightweight backdoor that steals cryptocurrency</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-discovers-new-lightweight-backdoor-that-steals-cryptocurrency-r35456/</link><description><![CDATA[<h3>
	Crypto Clipper spreads over USB and communicates over Tor.
</h3>

<p>
	Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.
</p>

<p>
	 
</p>

<p>
	The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination.
</p>

<h2>
	A lightweight backdoor
</h2>

<p>
	“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/" rel="external nofollow">said</a> Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”
</p>

<p>
	 
</p>

<p>
	Microsoft said it observed Crypto Clipper spreading through <a href="https://en.wikipedia.org/wiki/Shortcut_(computing)#Microsoft_Windows" rel="external nofollow">.lnk</a> file on a USB drive. These files store executable code. When an infected USB drive is plugged into a device, the code checks whether it is already installed on the machine. If it isn’t, the malware downloads it through the Tor proxy. To better conceal evidence of the worm, the malware scans the infected USB drive and names the .lnk files with similar names.
</p>

<figure class="ars-wp-img-shortcode id-2159894 align-none">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="crypto-clipper.webp" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2026/06/crypto-clipper.webp">
				<div class="pswp-caption-content" id="caption-2159894">
					<em>High-level execution flow of Crypto Clipper. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Credit: Microsoft </em></em>
					</div>
					<em> </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	Crypto Clipper monitors clipboard contents for patterns that are consistent with standardized 12- or 24-word seed phrases. When found, it uploads them, along with the screenshots, to the attacker’s server. The stealer also replaces addresses it finds with ones belonging to attacker-controlled wallets. This allows the malware to divert payments to the attacker’s pockets. Microsoft believes the purpose of the screenshots is to provide context that may be useful.
</p>

<p>
	 
</p>

<p>
	“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking,” Microsoft said. “The combination of Tor-routed C2, clipboard targeting, screenshot capture, and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices.”
</p>

<p>
	 
</p>

<p>
	Microsoft Defender for Endpoint detects Crypto Clipper components as Suspicious JavaScript processes and Possible data exfiltrations using Curl. Microsoft Defender Antivirus detects it as Trojan: Win32/CryptoBandits.A. More generically, the strongest indications of infection are script interpreters spawning suspicious child processes, proxy usage on localhost:9050, screen-capture commands in PowerShell, and signs of clipboard inspection or crypto-address replacement.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/06/microsoft-spots-new-self-propagating-malware-for-stealing-cryptocurrency/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 19 June 2026 at 12:55 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35456</guid><pubDate>Fri, 19 Jun 2026 02:55:49 +0000</pubDate></item><item><title>Why Microsoft Authenticator ditched multiple-choice logins</title><link>https://nsaneforums.com/news/security-privacy-news/why-microsoft-authenticator-ditched-multiple-choice-logins-r35447/</link><description><![CDATA[<h3>
	Slashed guessing odds are a nice bonus, but changing the app from multiple-choice to manual typing is really about stopping accidental approvals and spam attacks.
</h3>

<p id="elk-d8df745c-9e48-4425-a3b5-74e4a12367b5">
	The next time you open Microsoft Authenticator to log in to a device, you could be met with a new interface. Microsoft is rolling out a change that requires you to enter a number manually rather than tapping one of three options.
</p>

<p>
	 
</p>

<p>
	The update first appeared for enterprise and education users, but it has since started rolling out to personal Microsoft accounts. We've seen the new prompt appear on a personal device, suggesting the rollout is in progress.
</p>

<p>
	 
</p>

<p>
	<a id="elk-seasonal" rel=""></a>
</p>

<p id="elk-d8df745c-9e48-4425-a3b5-74e4a12367b5-2">
	At first glance, you may think that the change makes Microsoft Authenticator 33 times more secure. That would be true if malicious actors were hacking into accounts by guessing the number that appeared.
</p>

<p>
	 
</p>

<p>
	Before the change, there were only three options available, giving a theoretical blind hacker around a 33 percent chance of guessing. By requiring a two-digit number to be entered manually, there is only a 1 percent chance of guessing it right.
</p>

<p>
	 
</p>

<p>
	But attacks centered on multi-factor authentication usually aren't guessing games. Bad actors often spam users with a bunch of prompts to authenticate in the hopes that the user will approve the prompt or guess the correct number.
</p>

<p>
	 
</p>

<p>
	Accidental approvals are also an issue. With only three numbers appearing on a screen, you could tap the correct number by accident when opening the app or moving the phone around in your pocket.
</p>

<p>
	 
</p>

<p>
	Requiring a number to be entered manually reduces those risks greatly.
</p>

<p>
	 
</p>

<p>
	Microsoft has made several changes to its authenticator app to improve security. SMS codes are being phased out as an option for personal Microsoft accounts because they are insecure. SMS-based authentication is the leading source of fraud, <a data-analytics-id="inline-link" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts" href="https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">explains Microsoft</a>.
</p>

<p>
	 
</p>

<p>
	The change to requiring manual number entry is more pinpointed than shifting away from SMS-based authentication, but it adds another layer of security.
</p>

<p>
	 
</p>

<p>
	The update is rolling out gradually, so you may not see it yet.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.windowscentral.com/software-apps/why-microsoft-authenticator-ditched-multiple-choice-logins" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 19 June 2026 at 8:22 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35447</guid><pubDate>Thu, 18 Jun 2026 22:23:08 +0000</pubDate></item><item><title>Android verification is coming: Google confirms timeline and supported app stores</title><link>https://nsaneforums.com/news/security-privacy-news/android-verification-is-coming-google-confirms-timeline-and-supported-app-stores-r35446/</link><description><![CDATA[<h3>
	A new system service will roll out this month ahead of big changes starting in September.
</h3>

<p>
	Almost 20 years ago, Google pitched Android as the more open alternative to Apple’s walled garden. Last year, Google announced it would <a href="https://arstechnica.com/gadgets/2025/08/google-will-block-sideloading-of-unverified-android-apps-starting-next-year/" rel="external nofollow">begin erecting its own walls</a> through developer verification. The company has issued an update on its plans, affirming that the verification system will begin rolling out in select countries later this year. We’re also learning which app stores are participating in verification and the timeline for key features like the recently revealed “advanced flow” for bypassing verification.
</p>

<p>
	 
</p>

<p>
	Google has claimed that developer verification is a necessary change to smartphone software distribution, pointing to the increased prevalence of scams that trick Android users into installing malware apps. Google’s solution requires verifying the identities of developers outside the Play Store just like it does for devs publishing on its platform. This has <a href="https://arstechnica.com/gadgets/2026/03/with-developer-verification-googles-apple-envy-threatens-to-dismantle-androids-open-legacy/" rel="external nofollow">proven to be a contentious change</a> for myriad reasons.
</p>

<p>
	 
</p>

<p>
	In the <a href="https://android-developers.googleblog.com/2026/06/android-developer-verification.html" rel="external nofollow">new blog post</a>, Google’s Matthew Forsythe confirms that the developer verification system is slated to come online on September 30 of this year. The initial deployment will be limited to countries with a high level of app scams: Brazil, Indonesia, Singapore, and Thailand.
</p>

<p>
	 
</p>

<p>
	Google released its new developer console back in March, inviting external developers the <a href="https://arstechnica.com/gadgets/2025/10/google-confirms-android-dev-verification-will-have-free-and-paid-tiers-no-public-list-of-devs/" rel="external nofollow">opportunity to pay $25</a> and verify their identities early. Developers who don’t register will find that their apps cannot be sideloaded on Google-certified Android devices once verification has rolled out. Google says that almost every app in the Play Store is now ready for the change, and a “large majority” of apps outside Google Play have completed verification.
</p>

<p>
	 
</p>

<p>
	This system places more burden on developers who want to make software for Android, even if they don’t want to deal with Google directly. There are a few updates that aim to streamline the experience. Google is following through on its promise to extend verification to trusted third-party stores—if a developer is verified in one of these storefronts, they are verified on Google’s side. Google says it will verify the apps in the following stores when it begins enforcing the new restrictions.
</p>

<p>
	 
</p>

<ul>
	<li>
		Google (Google Play)
	</li>
	<li>
		Honor (HONOR App Market)
	</li>
	<li>
		OPlus (OPPO App Market)
	</li>
	<li>
		Samsung (Galaxy Store)
	</li>
	<li>
		Transsion (Palm Store)
	</li>
	<li>
		vivo (V-Appstore)
	</li>
	<li>
		Xiaomi (GetApps)
	</li>
</ul>

<p>
	 
</p>

<p>
	Developers will also have access to new APIs to make registering as an external developer less arduous. In the coming months, Google will release an Android Developer ID Status API that will check if a package name is already registered with Google. The Android Developer Console API will let you register and manage your app package names without leaving your development environment, too.
</p>

<h2>
	The countdown begins
</h2>

<p>
	The next step toward verifying apps will come this month as Google deploys a new system service on most certified devices. The package (com.google.android.verifier) will appear on phones and tablets running Android 8 or higher, allowing Google to block the installation of unverified apps. It will remain dormant until verification is activated in your specific region.
</p>

<figure class="ars-wp-img-shortcode id-2159861 align-fullwidth">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="260604_Blog-in-line-asset-ADV-June.png" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2026/06/260604_Blog-in-line-asset-ADV-June.png">
				<div class="pswp-caption-content" id="caption-2159861">
					<div class="ars-gallery-caption-credit">
						<em><em>Credit: Google</em></em>
					</div>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	In July, Google plans to roll out the new developer APIs and begin testing for “limited distribution” accounts. This is Google’s solution for hobbyists who want to make their own apps and share them with a small group. Limited accounts won’t require a fee or government ID verification, but you can install these apps on up to 20 devices.
</p>

<p>
	 
</p>

<p>
	In August, the advanced flow will become available globally ahead of verification becoming mandatory in the first markets. As <a href="https://arstechnica.com/gadgets/2026/03/google-details-new-24-hour-process-to-sideload-unverified-android-apps/" rel="external nofollow">detailed a few months ago</a>, the advanced flow will allow users to bypass verification, but the process isn’t easy. You’ll have to navigate to a buried menu, confirm you understand the risks multiple times, and wait a whole day before completing the process.
</p>

<p>
	 
</p>

<p>
	And that brings us to September, when Android devices in Brazil, Indonesia, Singapore, and Thailand will begin checking verification status before installing apps. However, things get murky after that. Google will undoubtedly monitor how verification works as millions of users are suddenly limited to verified apps, which could affect how it moves forward. Google says it intends to expand developer verification in 2027, eventually making it a global device policy.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2026/06/google-shares-updated-timeline-for-rolling-out-android-developer-verification/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 19 June 2026 at 8:21 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35446</guid><pubDate>Thu, 18 Jun 2026 22:22:05 +0000</pubDate></item><item><title>Windows and Linux users: The deadline to update Secure Boot keys is near</title><link>https://nsaneforums.com/news/security-privacy-news/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near-r35429/</link><description><![CDATA[<h3>
	What you need to know about the expiration of keys securing your machine’s boot sequence.
</h3>

<p>
	The clock is ticking for Windows and Linux users to update cryptographic keys that protect their systems against firmware-based UEFI infections, a pernicious form of malware that loads before operating system and anti-malware protections start.
</p>

<p>
	 
</p>

<p>
	Beginning June 24, three certificates that cryptographically verify that each piece of firmware and software that loads during system boot will expire. The Microsoft-signed certificates are the linchpins of Secure Boot, a Microsoft-designed chain of trust. Secure Boot checks the digital signatures of all firmware that loads during system startup to ensure it originates from a trusted provider, such as the manufacturer of the motherboard the system runs on.
</p>

<p>
	 
</p>

<p>
	Secure Boot is designed to thwart UEFI bootkits, a form of malware that alters the Unified Extensible Firmware Interface, the successor to the BIOS, both of which begin the initial boot sequence. Because these bootkits load before the OS and most other code, they can be difficult to detect. Once installed, they typically load malware onto the OS that steals credentials, backdoors the system, or performs other malicious actions. Even when the OS is disinfected, the bootkit can reinfect the system. Bootkits survive OS reinstallations as well.
</p>

<h2>
	A brief history of bootkits
</h2>

<p>
	The genesis of bootkits dates back to the early 1980s with the creation of <a href="https://elhacker.info/manuales/Virus/Rootkits%20and%20Bootkits_%20Reversing%20Modern%20Malware%20and%20Next%20Generation%20Threats%20Early%20Access.pdf" rel="external nofollow">several pieces of malware</a> that targeted Apple II machines during the boot process. They spread in the wild through floppy disks that ostensibly contained pirated games.
</p>

<p>
	 
</p>

<p>
	Windows bootkits gained notice in the early 2000s as proofs of concept developed by researchers of offensive security. BootRoot, a bootkit <a href="https://blackhat.com/presentations/bh-usa-05/bh-us-05-soeder.pdf" rel="external nofollow">demonstrated</a> at the 2005 Black Hat security conference, is likely the first such instance. The malware infected the Network Driver Interface, which streamlined communications between network protocol drivers enabling service such as TCP/IP network adapter drivers. In the years following, similar PoCs included <a href="https://blackhat.com/presentations/bh-europe-07/Kumar/Presentation/bh-eu-07-kumar-apr19.pdf" rel="external nofollow">Vbootkit</a>, the <a href="https://blackhat.com/presentations/bh-usa-09/KLEISSNER/BHUSA09-Kleissner-StonedBootkit-PAPER.pdf" rel="external nofollow">Stoned Bootkit</a>, and <a href="https://web.archive.org/web/20080111144919/http://www.symantec.com/security_response/writeup.jsp?docid=2008-010718-3448-99" rel="external nofollow">Mebroot</a>. There were many more.
</p>

<p>
	 
</p>

<p>
	In 2012, a new form of bootkit was demonstrated. Instead of targeting machines through the BIOS or master boot record, <a href="https://web.archive.org/web/20121101094905/http://ho.ax/De_Mysteriis_Dom_Jobsivs_Black_Hat_Paper.pdf" rel="external nofollow">one</a> such bootkit attacked Mac OS X systems by infecting the EFI, a package of firmware that started the boot process. A <a href="https://web.archive.org/web/20121006171515/http://www.itsec.it/2012/09/18/uefi-technology-say-hello-to-the-windows-8-bootkit/" rel="external nofollow">second</a> very primitive bootkit targeted Windows 8 machines by infecting the <a href="https://en.wikipedia.org/wiki/UEFI" rel="external nofollow">UEFI bootkit</a>, the predecessor to the UEFI. Around 2013, a researcher demonstrated a more advanced UEFI bootkit for Windows named <a href="https://web.archive.org/web/20140207025247/https://www.quarkslab.com/dl/13-04-hitb-uefi-dreamboot.pdf" rel="external nofollow">Dreamboat</a>.
</p>

<p>
	 
</p>

<p>
	The first known case of a real-world attack targeting the UEFI came in 2018 with the discovery of malware dubbed <a href="https://arstechnica.com/information-technology/2018/10/first-uefi-malware-discovered-in-wild-is-laptop-security-software-hijacked-by-russians/" rel="external nofollow">LoJax</a>. A repurposed version of legitimate anti-theft software known as LoJack, it was created by the Kremlin-backed hacking group tracked under names including Sednit, Fancy Bear, and APT 28. The malware was installed remotely using malware tools that can read and overwrite parts of the UEFI firmware’s flash memory.
</p>

<p>
	 
</p>

<p>
	In 2020, researchers unearthed the second known instance of real-world malware attacking the UEFI. Each time an infected device rebooted, its UEFI checked whether a malicious file was present in the Windows startup folder and, if not, installed it. Researchers from Kaspersky, the security provider that discovered the malware, named it “<a href="https://arstechnica.com/information-technology/2020/10/custom-made-uefi-bootkit-found-lurking-in-the-wild/" rel="external nofollow">MosaicRegressor</a>.” Researchers have yet to determine how the compromised UEFIs became infected. Since then, a handful of new UEFI bootkits have come to light. They are tracked under names including ESpecter, FinSpy, and MoonBounce.
</p>

<h2>
	Necessity is the mother of invention
</h2>

<p>
	In response to the more menacing threat of UEFI bootkits, Microsoft worked with device makers to develop Secure Boot, an industry-wide standard that uses cryptographic signatures to ensure that each piece of firmware loaded during startup is trusted by a computer’s manufacturer. Secure Boot is designed to create a chain of trust that prevents attackers from replacing the intended bootup firmware with malicious firmware. If a single link in the startup chain isn’t recognized, Secure Boot will prevent the device from starting.
</p>

<p>
	 
</p>

<p>
	Then in 2023, researchers discovered <a href="https://arstechnica.com/security/2023/12/just-about-every-windows-and-linux-device-vulnerable-to-new-logofail-firmware-attack/" rel="external nofollow">LogoFail</a>, a series of critical vulnerabilities found UEFIs booting up just about every Windows and Linux system in the world. An image-parsing bug in the software that presented hardware manufacturers’ logos during bootup allowed attackers to bypass Secure Boot and infect the UEFI with malicious firmware.
</p>

<p>
	 
</p>

<p>
	The discovery of LogoFail requires Microsoft to replace the existing cryptographic signatures underpinning Secure Boot with new ones. Three older signatures, which are dated 2011, are being removed. In their place are ones dated 2023. Microsoft is in the process of updating Windows 10 and Windows 11 machines. Linux distributors are also in the process of updating “shims,” a small, first-stage UEFI bootloader that acts as a trusted bridge between Secure Boot keys and the Linux bootloader.
</p>

<p>
	 
</p>

<p>
	Machines that fail to update the Secure Boot-related keys will continue to function, but they will no longer be protected against new UEFI threats. To be clear, they were already vulnerable to new UEFI threats that exploited the industry-wide LogoFail vulnerability. The key refresh is designed to mitigate that risk and prevent unrelated UEFI attacks that may arise in the future.
</p>

<p>
	 
</p>

<p>
	To check the status of the keys on Windows machines, users can open Windows Security settings &gt; Device Security &gt; Secure Boot. A green checkmark means the update has been completed. Most Windows machines automatically update the keys during regular monthly patch distributions, but older machines may require manual attention. Linux users should watch for the release of new shims. If at all possible, users should hold off on installing new motherboard firmware updates until after the new certificates are replaced.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/06/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 18 June 2026 at 2:27 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35429</guid><pubDate>Thu, 18 Jun 2026 04:28:01 +0000</pubDate></item><item><title>Steam Workshop abused to spread malware via Wallpaper Engine app</title><link>https://nsaneforums.com/news/security-privacy-news/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app-r35427/</link><description><![CDATA[<p style="text-align:center;">
	<span><strong>Steam Workshop abused to spread malware via Wallpaper Engine app</strong></span>
</p>

<p>
	 
</p>

<p>
	Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages.
</p>

<p>
	Infected wallpapers can lead to hijacking Steam accounts, compromising the system with a backdoor, or running crypto mining processes.
</p>

<p>
	Steam Workshop is a built-in content-sharing platform on Valve's Steam gaming service where users can upload and download community-created content for games and applications.
</p>

<p>
	The content includes mods, maps, skins, save files, tools, and other user-generated content such as wallpapers.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<span><strong>Malware in the wallpaper</strong></span>
</p>

<p style="text-align:center;">
	 
</p>

<p>
	In a report today, researchers at cybersecurity company Kaspersky say that the attacks abuse the Wallpaper Engine desktop customization application available on Steam, which has <span><a href="https://steamdb.info/app/431960/" rel="external nofollow">nearly a million reviews.</a></span>
</p>

<p>
	Wallpaper Engine supports four wallpaper types that render videos, interactive scenes, web pages that can play audio and video, and applications, which are active windows from software that Wallpaper Engine sets as the desktop background.
</p>

<p>
	 
</p>

<p>
	Application wallpapers are executable Windows applications that can include games, desktop widgets, and system monitoring tools.<a href="https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/" rel="external nofollow"> Kaspersky warns</a> that the feature represents a built-in security risk and has been abused to deliver malware to Steam users.
</p>

<p>
	 
</p>

<p>
	According to the researchers, attackers took advantage of this security gap since at least late 2025, uploading malicious wallpaper files to the Steam Workshop and tricking users into installing them through Wallpaper Engine.
</p>

<p>
	"We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times," Kaspersky notes.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="Malicious wallpaper application Source: Kaspersky" class="ipsImage" data-ratio="54.86" height="395" style="width:720px;height:auto;" width="720" src="https://imgupload.pl/images/2026/06/18/imageadc23647b3c9b29c.png" />
</p>

<p>
	 
</p>

<p>
	Analysis of compromised wallpapers revealed that the malware is bundled either directly in the package or inside password-protected archives that the user is tricked into opening.
</p>

<p>
	The payloads execute automatically the moment the user installs the wallpaper, the researchers say.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="Observed attack flow Source: Kaspersky" class="ipsImage" data-ratio="48.61" height="349" style="width:720px;height:auto;" width="720" src="https://imgupload.pl/images/2026/06/18/imagebbc1510dab94cf4b.png" />
</p>

<p>
	 
</p>

<p>
	Kaspersky tested one of these wallpapers posing as a game called NTRaholic, which launched as expected upon execution to reduce suspicion. However, a backdoor file part of the DarkKomet malware family was installed in the background.
</p>

<p>
	 
</p>

<p>
	A custom version of a system library called 'AggregatorHost.dll' was also installed to search for Steam accounts on the computer and steal account credentials.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="Stealing Steam data Source: Kaspersky" class="ipsImage" data-ratio="40.97" height="294" style="width:720px;height:auto;" width="720" src="https://imgupload.pl/images/2026/06/18/imagee6d9936c5e1e703f.png" />
</p>

<p>
	 
</p>

<p>
	The researchers found multiple cases involving other malware families, such as the Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and even ransomware strains, showing that Wallpaper Engine was abused by multiple threat actors.
</p>

<p>
	 
</p>

<p>
	While Steam has identified and removed all the malicious wallpaper applications that Kaspersky identified, but researchers are warning that threat actors are likely to submit new ones.
</p>

<p>
	Apart from downloading content from trusted sources, Kaspersky recommends users to scan anything fetched from Steam Workshop using an up-to-date antivirus product.
</p>

<p>
	 
</p>

<pre class="ipsCode">Source : https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/</pre>

<p>
	 
</p>
]]></description><guid isPermaLink="false">35427</guid><pubDate>Thu, 18 Jun 2026 01:43:26 +0000</pubDate></item><item><title>Nearly a million passports and photo IDs were left unprotected on the public internet</title><link>https://nsaneforums.com/news/security-privacy-news/nearly-a-million-passports-and-photo-ids-were-left-unprotected-on-the-public-internet-r35365/</link><description><![CDATA[<h3>
	This should be a wakeup call for data security.
</h3>

<p>
	Typing a few letters and numbers into my web browser, I find myself gaping at the identity documents of complete strangers. The passport of a young woman from Germany. The passport of a man from Spain with glasses resting on his head. The front and back of another man’s driver’s license, a stereotypically goofy expression on his face.
</p>

<p>
	 
</p>

<p>
	They were all sitting unprotected at public URLs, with no password or access control of any sort. If I sent you a link, you could have looked at someone’s passport.
</p>

<p>
	 
</p>

<p>
	“We have to do something about it as fast as possible, because people will find this and resell it. It will do damage,” Sammy Azdoufal told me in May.
</p>

<p>
	 
</p>

<p>
	Azdoufal is the security researcher who used Claude Code to help discover that <a href="/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt" rel="">every DJI Romo robot vacuum cleaner</a> and <a href="/tech/926487/meari-technology-hack-baby-monitor-security-camera" rel="">a million baby monitors and security cameras</a> were embarrassingly easy to hack. This time, he says he discovered over 985,000 photo IDs sitting on the public internet for any half-decent hacker to steal.
</p>

<p>
	 
</p>

<p>
	If you’ve visited a cannabis club in Spain, Azdoufal says, chances are your photo ID was among them — and possibly your phone number, address, your favorite strains of cannabis, and how much you consumed each month while there. Azdoufal says celebrities are in the database, too, and visitors from all over the world, including 30,000 from the United States. “They have famous people,” says Azdoufal. “People who don’t want everyone to know they smoke weed.”
</p>

<p>
	 
</p>

<p>
	Here’s a rough summary of the userbase that Azdoufal’s automated tool was able to see, and the names of some of the clubs:
</p>

<p>
	 
</p>

<div>
	<div class="_1044qizj">
		<div>
			<div class="duet--media--content-warning _1k8kvzd0">
				<div class="duet--article--image-gallery-image _1pegheu0" id="dmcyOmltYWdlOjk0NzE5OA==">
					<a class="_1pegheu1" data-pswp-height="1071" data-pswp-width="1512" href="https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0,0,100,100" rel="external nofollow" target="_blank"><img alt="The image shows that Spain, Italy, France, South Africa, and Britain are the top five nationalities represented, and names various clubs, primarily in Barcelona." class="i7ks070" data-chromatic="ignore" data-nimg="fill" decoding="async" loading="lazy" sizes="(max-width: 639px) 100vw, (max-width: 1023px) 50vw, 700px" srcset="https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=256 256w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=376 376w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=384 384w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=415 415w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=480 480w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=540 540w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=640 640w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=750 750w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=828 828w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1080 1080w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1200 1200w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1440 1440w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1920 1920w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=2048 2048w, https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=2400 2400w" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/ccs-puffpal-dataset.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=2400"></a>
				</div>
			</div>
		</div>

		<div class="duet--media--caption _77sxmb0">
			<cite class="duet--article--dangerously-set-cms-markup _19wv7tc2 _77sxmb5">Image: Sammy Azdoufal</cite>
		</div>

		<div class="duet--media--caption _77sxmb0">
			 
		</div>
	</div>
</div>

<p>
	It’s not the clubs that didn’t protect these identity documents. An Irish company called Cannabis Club Systems (CCS), formally Nefos Solutions, develops and provides the software these clubs use for sales, accounting, and admissions, including a verification system where receptionists upload your IDs and selfies to Nefos’ cloud.
</p>

<p>
	 
</p>

<p>
	Traditionally, you’d need to provide a photo ID every time you wanted to get into a club. But with the verification system, the receptionist can pull up your stored identity documents and check if your face matches. There’s also an optional app called PuffPal that lets clubs scan a QR code for faster entry.
</p>

<p>
	 
</p>

<p>
	But when Azdoufal decompiled that PuffPal app, <a href="https://github.com/xn0tsa/because-i-got-high" rel="external nofollow">he explains in his report</a>, he discovered that Nefos had no meaningful level of security. He discovered a secret key for the Stripe payments platform sitting inside the app in plain text. He discovered he could pull up any member’s profile just by changing one number. If those profiles included their phone number, home address, passport, and weed preferences, he now had access to them too.
</p>

<p>
	 
</p>

<p>
	And then, he discovered that those passports, drivers licenses, and photo IDs were stored at public URLs as simple as this: <a href="https://ccsnubev2.com/v8/images/_%7Bclub%7D/ID/%7Buser_id%7D-front.jpg" ipsnoembed="false" rel="external nofollow">https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg</a>
</p>

<p>
	 
</p>

<p>
	Those clubs were uploading 5,000 new photo IDs with these insecure URLs every day, Azdoufal tells me.
</p>

<p>
	 
</p>

<p>
	He also found an admin portal accessible via the public internet — and that the cannabis clubs had a trivial level of security on their own accounts, using passwords that could theoretically be cracked in minutes with a modern GPU. Private chat messages between clubs and members through the PuffPal app were also vulnerable.
</p>

<p>
	 
</p>

<p>
	The good news: roughly a month after we reached out to Nefos, the company seems to finally be taking meaningful action. The company says it’s shutting down its entire PuffPal system and vulnerable APIs until they can be fixed — in Azdoufal’s latest tests on June 10th, passport images and personal data seem to be secure. Nefos has also informed local authorities, and says it will take responsibility to make fixes, pay fines, and tell users what happened.
</p>

<p>
	 
</p>

<p>
	In a phone interview, Nefos co-founder Andreas Nilsen tells <em>The Verge</em> that he’s in touch with Ireland’s Data Protection Authority (DPC) about the data breach — a fact that DPC spokesperson Evan O’Leary confirmed to us by email. “We have to communicate to everyone that was potentially exposed,” Nilsen tells me, saying he hopes the DPC can show his company how to do that properly. Nilsen claims there’s currently no evidence that any outsider accessed the data other than Azdoufal.
</p>

<p>
	 
</p>

<p>
	But it took far too long for Nefos to take the threat seriously. It took five days and the threat of a story before the company replied to us, long after Azdoufal reached out. Then, Nefos began by papering over the holes instead of risking business.
</p>

<p>
	 
</p>

<p>
	I was prepared to write this story at the beginning of June, after Azdoufal told me Nefos had finally locked down the passport images. But on June 4th, I surprised Azdoufal by showing him that his very own passport was online once again, without any protection.
</p>

<p>
	 
</p>

<p>
	That’s because Nefos had not yet stopped cannabis clubs from using the PuffPal app, and clubs were complaining the locked-down images weren’t showing up the way they used to — so Nefos simply unlocked the images again. While Nilsen claims the images were locked down “70 percent of the time” since Azdoufal and I got in touch, it’s pretty clear that Nefos made a decision to prioritize its customers instead of the threat.
</p>

<p>
	 
</p>

<p>
	On June 9th, Azdoufal discovered that even though Nefos had locked down the passport images and photo IDs with tokens, <em>everything else</em> in the user profiles was still easily accessible: passport numbers, phone numbers, email addresses, home addresses, everything.
</p>

<p>
	 
</p>

<p>
	All a hacker had to do was type “curl -X POST <a href="https://ccsnubev2.com/v8/api/userProfile.php" ipsnoembed="false" rel="external nofollow">https://ccsnubev2.com/v8/api/userProfile.php</a> -d “user_id=[NUMBER]&amp;[CLUB NAME]=test&amp;language=en” into a command line, and the servers would freely give up a ream of personal information. After we brought this to Nefos’ attention, that hole, too, has been closed.
</p>

<p>
	 
</p>

<p>
	But how could the company be so careless? “I don’t want to put the blame on others because at the end of the day it resides with us,” Nilsen says. But he does point the finger <a href="https://www.9series.com/" rel="external nofollow">at 9Series</a>, an outsourcing firm he claims was responsible for developing the PuffPal app and creating all the vulnerable APIs it used to pull unprotected data from Nefos’ user database. (9Series did not have a response by publish time.)
</p>

<p>
	 
</p>

<p>
	Now that PuffPal is down, Nefos is emailing every club to let them know their members won’t be able to use those QR codes for entry — but they can still pull up IDs from Nefos’ servers after scanning a member’s RFID card or typing in their phone number, among other examples.
</p>

<p>
	 
</p>

<p>
	Nilsen claims his company will not simply re-launch unsecured PuffPal if the clubs ask. “We’re going to tell them we can’t,” he says. “We will make sure, after this debacle, that this is verified by an independent security researcher and guarantee that this is 100 percent secure.” He says Nefos is parting ways with 9Series, and hopes to have a new app within a few months.
</p>

<p>
	 
</p>

<p>
	Nilsen says he’s aware that <a href="https://gdpr.eu/what-is-gdpr/" rel="external nofollow">under EU law</a>, his company legally had to disclose the breach within 72 hours or pay significant fines, something the company didn’t do<em>.</em> “I’m sure we’ll get whatever kind of penalty there is,” Nilsen says.
</p>

<p>
	 
</p>

<p>
	Just last month, a website called the UK Visa Portal <a href="https://techcrunch.com/2026/05/27/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/" rel="external nofollow">similarly exposed at least 100,000 passports</a> to anyone who could guess a URL. Let’s hope this is a wakeup call.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/tech/947157/passports-data-breach-cannabis-club-systems-nefos-puffpal" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 11 June 2026 at 2:29 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35365</guid><pubDate>Thu, 11 Jun 2026 04:30:12 +0000</pubDate></item><item><title>Microsoft: Windows 11 KB5094126, KB5093998 finally stops trusting a critical system threat</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-windows-11-kb5094126-kb5093998-finally-stops-trusting-a-critical-system-threat-r35364/</link><description><![CDATA[<h3>
	Windows June 2026 update hides untrusted desktop.ini folder customizations for security. However there are ways to restore trust.
</h3>

<p>
	This week Microsoft released the Patch Tuesday updates for June 2026 with <a href="https://www.neowin.net/news/windows-11-kb5094126-june-2026-patch-tuesday-update-now-available-to-download/" rel="external nofollow">KB5094126</a> on Windows 11 25H2, 24H2, and <a href="https://www.neowin.net/news/windows-10-kb5094127-patch-tuesday-improves-file-explorer-search-and-more/" rel="external nofollow">KB5093998</a> on Windows 11 23H2. On Windows 10 22H2 it's under <a href="https://www.neowin.net/news/windows-10-kb5094127-patch-tuesday-improves-file-explorer-search-and-more/" rel="external nofollow">KB5094127</a>.
</p>

<p>
	 
</p>

<p>
	Alongside the announced release notes for the new builds, Microsoft has revealed another change that is coming to Windows with these new releases. It has been confirmed that custom folders are getting a significant change with the June 2026 updates as such folders or folder names defined by desktop.ini will no longer appear after this update is successfully installed. While you may inititally think this is a bug with the new release, Microsoft has stated that this is in fact "expected behaviour" in its new support article regarding this which Neowin spotted today while browsing.
</p>

<p>
	 
</p>

<p>
	Essentially it's a security hardening measure such that custom folder presentations are treated as potentially unsafe whenever Windows is not sure about their origin and whether that desktop.ini folder can be trusted or not. Here is list of such untrusted files and folders:
</p>

<p>
	 
</p>

<ul>
	<li>
		<p>
			Files downloaded from the internet that carry Mark-of-the-Web (MOTW).
		</p>
	</li>
	<li>
		<p>
			Files copied from certain remote locations, such as some WebDAV or HTTP-based locations.
		</p>
	</li>
	<li>
		<p>
			Files on network paths that are not classified as intranet or trusted by zone policy.
		</p>

		<p>
			 
		</p>
	</li>
</ul>

<p>
	For those who may not be familiar, Desktop.ini is a special configuration file used by Windows to customize the appearance and behavior of individual folders. Basically Windows can read specific instructions stored in Desktop.ini instead of displaying every folder with the same default settings. This can be used to apply custom icons, thumbnail images, localized folder names, and such informational tooltips (infotip). The file can also influence certain folder-specific behaviors and properties. It is typically stored as a hidden system file within a folder that has been designated to support Desktop.ini customization.
</p>

<p>
	 
</p>

<p>
	However, because Windows Shell automatically reads and applies these attributes whenever a customized folder is opened, they have historically (since the Windows XP days) presented an attack surface as a result of an unchecked buffer in the Shell component responsible for extracting custom attributes from Desktop.ini files. As such an attacker could create a specially crafted Desktop.ini containing a malicious or corrupted attributes and place it on a network share.
</p>

<p>
	 
</p>

<p>
	So if a user were to browse that folder, Windows would automatically process the file, potentially triggering a buffer overflow. This could allow arbitrary code to run with the same permissions as the logged-in user. Hence a seemingly harmless folder could become a security risk when their contents are not properly validated.
</p>

<p>
	 
</p>

<p>
	For admins and users alike looking to manage this behaviour, Microsoft has shared a few ways. One of them is to assign a trusted mark on the folder in case you are sure of its source. Secondly a policy can be used to revert back to the previous state. Finally, the MOTW can be removed too to indicate to Windows that this is a safe file.
</p>

<p>
	 
</p>

<p>
	The company explains:
</p>

<p>
	 
</p>

<p>
	<strong>Option 1: Add the source to Trusted Sites (Recommended)</strong>
</p>

<p>
	 
</p>

<p>
	If the affected content is stored on a known internal or managed source, add that source to the <strong>Trusted Sites</strong> list. Once the source is treated as trusted, Windows processes <strong>desktop.ini</strong> from that source normally. This keeps the protection in place for other locations and is the lower-risk option.
</p>

<p>
	 
</p>

<p>
	<strong>Option 2: Use policy to restore previous behavior</strong>
</p>

<p>
	 
</p>

<p>
	Organizations that need broader compatibility can enable the policy <strong>Allow the use of remote paths in file shortcut icons</strong>.Enabling this policy restores the pre-June 2026 behavior for affected remote or untrusted scenarios.
</p>

<p>
	 
</p>

<p>
	<strong>Option 3: Check for and remove the Mark of the Web (MotW)</strong>
</p>

<p>
	 
</p>

<p>
	If the desktop.ini file has a Mark of the Web (MotW), Windows may treat it as coming from an untrusted source and block customization. Verify whether MotW is present and, if appropriate, remove it from the desktop.ini file. This can restore expected behavior, but should only be done for trusted content, as it removes the associated security protection.
</p>

<p>
	 
</p>

<p>
	To remove the MotW tag, open PowerShell and run one of the following commands:
</p>

<p>
	 
</p>

<ul>
	<li>
		<p>
			<strong>For a single desktop.ini file:</strong>
		</p>

		<p>
			 
		</p>

		<div class="ocpAlert">
			<p>
				<code>Unblock-File "C:\Your\Folder\Path\desktop.ini"</code>
			</p>

			<p>
				 
			</p>
		</div>
	</li>
	<li>
		<p>
			<strong>For all desktop.ini files in a folder:</strong>
		</p>

		<p>
			 
		</p>

		<div class="ocpAlert">
			<p>
				<code>Get-ChildItem "C:\Your\Folder\Path" -Recurse -Filter desktop.ini -Force | Unblock-File</code>
			</p>

			<p>
				 
			</p>
		</div>
	</li>
</ul>

<p>
	Microsoft has warned though against using a broad opt-out using the provided policy as it reduces protection against potentially malicious remote folder-customization content. As such the tech giant recommends trusting only controlled internal sources and keeping trust settings as strict as possible. You can check out the official support article <a href="https://support.microsoft.com/en-us/topic/custom-folder-icons-or-localized-folder-names-might-not-appear-after-installing-the-june-2026-windows-security-update-f105e47a-3bfb-4e64-b757-767cfcdce07a" rel="external nofollow">here</a> on Microsoft's website.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-windows-11-kb5094126-kb5093998-finally-stops-trusting-a-critical-system-threat/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 11 June 2026 at 2:27 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35364</guid><pubDate>Thu, 11 Jun 2026 04:28:34 +0000</pubDate></item><item><title>Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed</title><link>https://nsaneforums.com/news/security-privacy-news/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed-r35347/</link><description><![CDATA[<h3>
	A separate zero-day also disclosed by Nightmare Eclipse appears to be patched as well.
</h3>

<p>
	Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant.
</p>

<p>
	 
</p>

<p>
	Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-days that had the potential to be exploited in the wild. The researcher has said the disclosures, which included proof-of-concept code, came after Microsoft reneged on an arrangement the two made regarding vulnerabilities they had discussed.
</p>

<h2>
	Disclosure drama
</h2>

<p>
	“But someone violated our agreement and left me homeless with nothing,” Nightmare Eclipse <a href="https://deadeclipse666.blogspot.com/2026/03/" rel="external nofollow">wrote</a> in March. “They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”
</p>

<p>
	 
</p>

<p>
	As part of June’s vulnerability patch batch release, Microsoft issued a fix for <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586" rel="external nofollow">CVE-2026-45586</a>. Nightmare Eclipse disclosed the vulnerability and limited PoC code in May under the name <a href="https://web.archive.org/web/20260520184528/https://github.com/Nightmare-Eclipse/GreenPlasma" rel="external nofollow">GreenPlasma</a>. The vulnerability is a local privilege escalation, meaning it can be chained to a separate vulnerability to give users or processes with low-level privileges the ability to defeat OS protections and gain full SYSTEM rights needed to install malware.
</p>

<p>
	 
</p>

<p>
	Microsoft said CVE-2026-45586 required minimal complexity to exploit, required no user interaction, and that chances of active exploitation in the wild were likely. The vulnerability, the company added, was the result of “improper link resolution before file access (‘link following’) in [the] Windows Collaborative Translation Framework.” There are no indications that the vulnerability has been actively exploited so far.
</p>

<p>
	 
</p>

<p>
	Tuesday’s patch bundle also fixed <a href="https://web.archive.org/web/20260521144855/https://github.com/Nightmare-Eclipse/MiniPlasma" rel="external nofollow">MiniPlasma</a>, a separate vulnerability disclosed by Nightmare Eclipse. Microsoft said in an email that the vulnerability is tracked as CVE-2020-17103, a vulnerability Microsoft first fixed six years ago. That means MiniPlasma was the result of a regression or an incomplete patch in its initial form. The company is in the process of updating Tuesday’s bulletin to note the republication.
</p>

<p>
	 
</p>

<p>
	Microsoft has yet to release patches for other vulnerabilities disclosed by Nightmare Eclipse. The company did <a href="https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/" rel="external nofollow">provide manual instructions</a> for mitigating YellowKey, a vulnerability that allows attackers to defeat Bitlocker full-disk encryption. That could be a boon when attackers have physical access to a device (the precise scenario Bitlocker is designed to protect against). The company has yet to fix the underlying cause of the vulnerability.
</p>

<p>
	 
</p>

<p>
	The status of other vulnerabilities disclosed by Nightmare Eclipse are also unclear at the moment. The researcher named one vulnerability, present in Windows Defender <a href="lhttps://web.archive.org/web/20260520184528/https://github.com/Nightmare-Eclipse/RedSun" rel="external nofollow">RedSun</a>. Another, named BlueHammer, is also a local privilege escalation flaw that provides SYSTEM rights.
</p>

<p>
	 
</p>

<p>
	Over the past few months, Nightmare Eclipse has taken multiple potshots at Microsoft. The specific criticisms remain unclear, but many make references to complaints about the company’s vulnerability disclosure program. Microsoft, in turn, has <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure" rel="external nofollow">publicly railed</a> against the researcher for “not responsibly” disclosing the vulnerabilities and made a vailed reference to the possibility of pursuing legal action. After a public backlash, Microsoft later relented and vowed no such legal action would occur.
</p>

<p>
	 
</p>

<p>
	On Tuesday, Nightmare Eclipse <a href="https://deadeclipse666.blogspot.com" rel="external nofollow">published</a> exploit code for a new Windows vulnerability. It’s a race condition that targets Defender.
</p>

<p>
	 
</p>

<p>
	Tuesday’s patch batch included fixes for roughly 200 vulnerabilities. Notwithstanding the appearance that MiniPlasma was fixed, two of them were also confirmed as zero-days.
</p>

<p>
	 
</p>

<p>
	<em>Post updated to include information Microsoft provided after initial publication of this post.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 10 June 2026 at 9:58 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of May) 2,092</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35347</guid><pubDate>Tue, 09 Jun 2026 23:58:24 +0000</pubDate></item></channel></rss>
