<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/24/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Security researchers uncover network of malicious Firefox extensions</title><link>https://nsaneforums.com/news/security-privacy-news/security-researchers-uncover-network-of-malicious-firefox-extensions-r30138/</link><description><![CDATA[<p>
	Security researchers at Zen Security have uncovered a malicious campaign targeting Firefox users through extensions. Firefox, like its Chromium-based counterparts, supports browser extension. These enable users to change functionality of the browser or the sites they visit.
</p>

<p>
	 
</p>

<p>
	Popular options <a data-wpel-link="internal" href="https://www.ghacks.net/2022/03/11/ublock-origin-is-now-the-most-popular-firefox-add-on/" rel="external nofollow">include content blockers</a>, video downloaders, or extensions that list coupons. Extensions uploaded to the Mozilla Store have to pass a series of tests designed to ensure that they are not malicious or problematic in other regards.
</p>

<p>
	 
</p>

<p>
	Only some extensions are reviewed manually by Mozilla, but that is still better than Google's "only automatic" handling of extension checks when they are uploaded to the official Store.
</p>

<p>
	 
</p>

<p>
	The malware campaign in question used extensions to "impersonate legitimate wallet tools" from platforms such as Coinbase, MetaMask, Trust Wallet, or MyMonera according to Koi Security. Their main purpose was to steal wallet secrets, which put the assets of the user under immediate risk.
</p>

<p>
	 
</p>

<p>
	<a data-wpel-link="external" href="https://blog.koi.security/foxywallet-40-malicious-firefox-extensions-exposed-4c14419de486" rel="external nofollow" target="_blank">Koi Security notes</a> that the campaign is still ongoing and that some extensions are still available on the official Mozilla Firefox add-ons repository. The campaign itself has been active since at least April 2025 according to the researchers. They noticed new extension uploads "as recent as last week", suggesting that the "operating is still active, persistent, and evolving".
</p>

<p>
	 
</p>

<p>
	The main way of distributing the extension was through the official extensions store that Mozilla maintains.
</p>

<p>
	 
</p>

<p>
	The malicious extensions extract the wallet credentials directly from the websites they target to send the data to a remote server.
</p>

<p>
	 
</p>

<p>
	The researchers note that the malware group leveraged common tactics to gain community trust. The fake extensions mimicked the branding of the legitimate wallet extensions and used review inflation to increase the number of positive reviews.
</p>

<p>
	 
</p>

<p>
	They shared the screenshot of one of the extensions. Listed with less than 100 users on the official Mozilla add-ons repository, it managed to obtain several thousands of reviews, including more than 2,000 5-star reviews.
</p>

<p>
	 
</p>

<p>
	List of malicious Firefox extensions (according to Zen Security):
</p>

<p>
	 
</p>

<p>
	bitget-by-addon 
</p>

<p>
	bitget-by-addons 
</p>

<p>
	bitget-extension 
</p>

<p>
	btc-wallet 
</p>

<p>
	coinbasewallet 
</p>

<p>
	developer-trust 
</p>

<p>
	eth-for-edition 
</p>

<p>
	eth-wallet 
</p>

<p>
	ethereum-wallet 
</p>

<p>
	ethereum-wallet-crypto 
</p>

<p>
	fil-project 
</p>

<p>
	filfox 
</p>

<p>
	filfox-wallet 
</p>

<p>
	is-a-block-explorer 
</p>

<p>
	keplr-wallet 
</p>

<p>
	leap-wallet 
</p>

<p>
	metamask-addons 
</p>

<p>
	metamask-crypto-official 
</p>

<p>
	metamask-for-firefox 
</p>

<p>
	metamask-for-wallet 
</p>

<p>
	metamask-the-extension 
</p>

<p>
	metamaskext 
</p>

<p>
	mew-wallet-ethereum-defi-web3 
</p>

<p>
	mymonero-wallet official-metamask 
</p>

<p>
	official-metamask-wallet 
</p>

<p>
	okx-add 
</p>

<p>
	okx-addons 
</p>

<p>
	okx-wallet-extension 
</p>

<p>
	okx-wallet-extension1 
</p>

<p>
	phantom-ext-off 
</p>

<p>
	phantom-wallet-extension 
</p>

<p>
	trust-app trust-application 
</p>

<p>
	trust-bestwallet trust-cryp 
</p>

<p>
	trust-developer 
</p>

<p>
	trust-extension-wallet 
</p>

<p>
	trust-for-mozilla 
</p>

<p>
	trust-wallet-mozilla-add 
</p>

<p>
	wallet-for-bitcoin 
</p>

<p>
	wallet-for-trusr-crypto-wallet 
</p>

<p>
	wallet-for-trust 
</p>

<p>
	wallet-metamask-crypto-wallet
</p>

<p>
	 
</p>

<p>
	Firefox users who have installed wallet extensions in the past should verify that they are legitimate and not malicious by comparing names.
</p>

<h3>
	Closing Words
</h3>

<p>
	Extensions can be mighty useful, but they are also regularly used by cybercriminals for attacks. It is a regular occurrence, not only on the Mozilla Store but also the Chrome Web Store. Extensions with the recommended batch should be considered more secure than any other on the Mozilla Store. These extensions are reviewed manually and thus less likely to be malicious.
</p>

<p>
	 
</p>

<p>
	<em>Do you install browser extensions? How do you make sure that you do not install malicious extensions? Feel free to leave a comment down below.</em>
</p>

<p>
	 
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	<a href="https://www.ghacks.net/2025/07/09/security-researchers-uncover-network-of-malicious-firefox-extensions/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30138</guid><pubDate>Wed, 09 Jul 2025 18:33:11 +0000</pubDate></item><item><title>Bitcoin Depot breach exposes data of nearly 27,000 crypto users</title><link>https://nsaneforums.com/news/security-privacy-news/bitcoin-depot-breach-exposes-data-of-nearly-27000-crypto-users-r30137/</link><description><![CDATA[<p>
	Bitcoin Depot, an operator of Bitcoin ATMs, is notifying customers of a data breach incident that has exposed their sensitive information.
</p>

<p>
	 
</p>

<p>
	In the letter sent to affected individuals, the company informs that it first detected suspicious activity on its network last year on June 23.
</p>

<p>
	 
</p>

<p>
	Although the internal investigation was completed on July 18, 2024, a parallel investigation by federal agencies dictated that public disclosure of the incident should be withheld until it was completed.
</p>

<p>
	 
</p>

<p>
	“On July 18, 2024, the investigation was complete, and we identified your personal information contained within documents related to certain of our customers that the unauthorized individual obtained,” <a href="https://www.maine.gov/cgi-bin/agviewerad/ret?loc=2797" rel="external nofollow" target="_blank">explains Bitcoin Depot in the letter</a>.
</p>

<p>
	 
</p>

<p>
	“Unfortunately, we were not able to inform you sooner due to an ongoing investigation. Federal law enforcement requested that Bitcoin Depot wait to provide you notice until after they completed the investigation.”
</p>

<p>
	 
</p>

<p>
	The type of data that has been exposed in this incident varies from individual to individual and may include:
</p>

<p>
	 
</p>

<ul>
	<li>
		Full name
	</li>
	<li>
		Phone number
	</li>
	<li>
		Driver’s license number
	</li>
	<li>
		Address
	</li>
	<li>
		Date of birth
	</li>
	<li>
		Email address
	</li>
</ul>

<p>
	 
</p>

<p>
	Bitcoin Depot is one of the largest Bitcoin ATM networks in the United States, operating 8,800 machines in the U.S., Canada, and Australia.
</p>

<p>
	 
</p>

<p>
	The information exposed in this incident is similar to data typically collected during Know-Your-Customer verification processes that crypto ATM operations in the U.S. are obliged to comply with as per applicable FinCEN regulations.
</p>

<p>
	 
</p>

<p>
	The number of people exposed in this incident is <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/57c3f5ca-09ce-411d-b3ec-94d153f4920d.html" rel="external nofollow" target="_blank">estimated to nearly 27,000</a>.
</p>

<p>
	 
</p>

<p>
	Because the financial risk is related to cryptocurrency, letter recipients were not offered coverage through identity monitoring and theft protection services.
</p>

<p>
	 
</p>

<p>
	Instead, they are advised to maintain high alertness for signs of fraud, monitor their account statements, and consider placing a security freeze on their credit report.
</p>

<p>
	 
</p>

<p>
	In December 2024, a similar incident occurred at U.S. Bitcoin ATM operator Byte Federal, which disclosed a data breach <a href="https://www.bleepingcomputer.com/news/security/bitcoin-atm-firm-byte-federal-hacked-via-gitlab-flaw-58k-users-exposed/" rel="external nofollow" target="_blank">affecting 58,000 customers</a>.
</p>

<p>
	 
</p>

<p>
	In that case, the breach was caused by hackers exploiting a GitLab vulnerability to access a server hosting sensitive customer information.
</p>

<p>
	 
</p>

<p>
	BleepingComputer has contacted Bitcoin Depot about the security incident but a comment was not avaialble.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/bitcoin-depot-breach-exposes-data-of-nearly-27-000-crypto-users/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30137</guid><pubDate>Wed, 09 Jul 2025 18:29:26 +0000</pubDate></item><item><title>Gmail's latest feature helps you get rid of those pesky emails from LinkedIn</title><link>https://nsaneforums.com/news/security-privacy-news/gmails-latest-feature-helps-you-get-rid-of-those-pesky-emails-from-linkedin-r30121/</link><description><![CDATA[<p>
	Spam used to be a huge problem, but it is something that many <a automate_uuid="533217f3-932e-4f16-8381-8e3c4806e1bc" href="https://www.neowin.net/news/gmail-is-working-to-cut-down-on-spam-at-the-source-from-2024/" rel="external nofollow">email providers have worked around</a>. Since spam gets filtered out of your primary inbox in most cases, another major annoyance that many users currently face is unwanted emails from websites that they may have knowingly or unknowingly subscribed to. Now, Google is implementing a robust mechanism to get rid of this problem in Gmail as well.
</p>

<p>
	 
</p>

<p>
	Google has <a automate_uuid="6061b61d-52f8-4853-973d-0cd2d3596d1e" href="https://blog.google/products/gmail/new-manage-subscriptions-unsubscribe/" rel="external nofollow">started rolling out a new feature</a> in Gmail that enables its users to unsubscribe from certain email senders in a matter of seconds. This is made possible through a <strong>Manage subscriptions</strong> view that can be accessed from the left navigation panel. Once you click on it, you'll get a dedicated view showing you a list of senders, sorted by how frequently they blast you with emails.
</p>

<figure class="image image--expandable">
	<img alt="The Manage subscriptions view in Gmail" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1751992591_capture.webp">
</figure>

<p>
	As can be seen in the screenshot above, you can click the <strong>Unsubscribe</strong> button next to whichever senders are annoying you the most with frequent emails. You'll be greeted with a prompt asking you to confirm if you want to be removed from the mailing lists of the particular sender, and you just have to acknowledge that. However, Google has cautioned that it may take a few days for senders to stop contacting you via mailing lists.
</p>

<p>
	 
</p>

<p>
	This is a particularly useful feature, and one that can come in really handy when you are getting those "You have an invitation" emails from LinkedIn, or the likes. It is important to note that Gmail already offers unsubscribe options, but the Manage subscriptions tab just consolidates all senders in a single view and allows customers to unsubscribe from all mailing lists in a much quicker way. Google is currently rolling out this new view on Android, iOS, and the web in select countries; no concrete details have been shared regarding a wider rollout.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/gmails-latest-feature-helps-you-get-rid-of-those-pesky-emails-from-linkedin/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30121</guid><pubDate>Tue, 08 Jul 2025 17:34:59 +0000</pubDate></item><item><title>Microsoft Edge will soon warn you about compromised passwords</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-edge-will-soon-warn-you-about-compromised-passwords-r30120/</link><description><![CDATA[<p>
	Microsoft Edge has a pretty powerful and feature-packed password manager. Microsoft is so confident in it that <a automate_uuid="c2eff70e-7c66-4a6c-9c85-569946515549" href="https://www.neowin.net/news/microsoft-is-killing-its-password-manager-in-authenticator-to-make-everyone-use-edge/" rel="external nofollow">it killed its dedicated password</a> manager, Microsoft Authenticator (part of it), to move people to Microsoft Edge on mobile devices. While we all know what the real intention behind that move was, there is no denying that the password manager in Microsoft Edge is indeed very useful. Soon, it will become even better thanks to real-time password monitoring.
</p>

<p>
	 
</p>

<p>
	Last week, Microsoft released Edge 139 for testing in the Beta Channel, which is the final step before public release to all users. Its lengthy changelog contains an important upgrade for the password manager, namely the ability to issue warnings in real-time about compromised passwords.
</p>

<p>
	 
</p>

<p>
	Edge's new "in-context password breach notification system" tracks if saved credentials appear in <em>known </em>data breaches. Once a password or other sensitive data appears in a leak, Edge issues a warning and suggests taking immediate action, such as changing the password.
</p>

<p>
	 
</p>

<p>
	As of right now, the new password monitoring system is rolling out gradually to Edge Insiders, so if you have Edge 139 Beta running, it might take a few days before you get the new feature.
</p>

<p>
	 
</p>

<p>
	Other changes in Edge 139 Beta include upgrades to the Settings section, which now uses WebUI 2. Microsoft recently published a blog post detailing <a automate_uuid="e7e884ab-22d2-402c-b82a-aa7e9cfe8857" href="https://www.neowin.net/news/microsoft-edge-is-now-significantly-faster-than-before/" rel="external nofollow">significant performance upgrades</a>. Thanks to WebUI 2, Edge can render settings much faster than before. Besides performance upgrades, the updated section has "minor visual and content upgrades," such as "optimizing for concise wording of individual settings, simplifying the number of pages and reorganizing content, and creating a cohesive user interface."
</p>

<p>
	 
</p>

<p>
	You can check out the full release notes for Microsoft Edge 139 beta <a automate_uuid="c917a7f3-e28d-41cc-845c-514a605be957" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-beta-channel" rel="external nofollow">in the official documentation</a>. The update will be available in the Stable Channel on the week of August 7, 2025.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-edge-will-soon-warn-you-about-compromised-passwords/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30120</guid><pubDate>Tue, 08 Jul 2025 17:31:50 +0000</pubDate></item><item><title>Malicious Chrome extensions with 1.7M installs found on Web Store</title><link>https://nsaneforums.com/news/security-privacy-news/malicious-chrome-extensions-with-17m-installs-found-on-web-store-r30112/</link><description><![CDATA[<p>
	Almost a dozen malicious extensions with 1.7 million downloads in Google's Chrome Web Store could track users, steal browser activity, and redirect to potentially unsafe web addresses.
</p>

<p>
	 
</p>

<p>
	Most of the add-ons provide the advertised functionality and pose as legitimate tools like color pickers, VPNs, volume boosters, and emoji keyboards.
</p>

<p>
	 
</p>

<p>
	Researchers at Koi Security, a company providing a platform for security self-provisioned software, discovered the malicious extensions in Chrome Web Store and reported them to Google.
</p>

<p>
	 
</p>

<p>
	Some of the extensions are no longer present but many of them continue to be available.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Two of the Chrome extensions featuring tracking code" class="ipsImage" height="366" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/July/1.jpg">
		<figcaption>
			<em>Two of the Chrome extensions featuring tracking code<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	Many of those extensions are verified, have hundreds of positive reviews, and are featured prominently on the Chrome Web Store, misleading users about their safety.
</p>

<p>
	 
</p>

<p>
	Users should check for the following add-ons in Chrome browser and remove them as soon as possible:
</p>

<p>
	 
</p>

<ul>
	<li>
		Color Picker, Eyedropper — Geco colorpick
	</li>
	<li>
		Emoji keyboard online — copy&amp;paste your emoji
	</li>
	<li>
		Free Weather Forecast
	</li>
	<li>
		Video Speed Controller — Video manager
	</li>
	<li>
		Unlock Discord — VPN Proxy to Unblock Discord Anywhere
	</li>
	<li>
		Dark Theme — Dark Reader for Chrome
	</li>
	<li>
		Volume Max — Ultimate Sound Booster
	</li>
	<li>
		Unblock TikTok — Seamless Access with One-Click Proxy
	</li>
	<li>
		Unlock YouTube VPN
	</li>
	<li>
		Unlock TikTok
	</li>
	<li>
		Weather
	</li>
</ul>

<p>
	 
</p>

<p>
	One of them, ‘Volume Max — Ultimate Sound Booster,’ has also been <a href="https://layerxsecurity.com/blog/sleeper-sound-layerx-uncovers-malicious-sleeper-sound-management-extensions-with-nearly-1-5-million-users-worldwide/" rel="external nofollow" target="_blank">flagged by LayerX</a> researchers last month, who warned about its potential for spying on users; but no malicious activity could be confirmed at the time.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Risky Chrome extension flagged by two security teams" class="ipsImage" height="668" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/July/3.jpg">
		<figcaption>
			<em>Risky Chrome extension flagged by two security teams<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	According to the researchers, the malicious functionality is implemented in the background service worker of each extension using the Chrome Extensions API, registering a listener that is triggered every time a user navigates to a new webpage.
</p>

<p>
	 
</p>

<p>
	The listener captures the URL of the visited page and exfiltrates the information to a remote server along with a unique tracking ID for each user.
</p>

<p>
	 
</p>

<p>
	The server can respond with redirection URLs, hijacking the user’s browsing activity and potentially taking them to unsafe destinations that may enable cyberattacks.
</p>

<p>
	 
</p>

<p>
	Although the possibility is there, it should be noted that Koi Security has not observed malicious redirections in their testing.
</p>

<p>
	 
</p>

<p>
	Furthermore, the malicious code was not present in the initial versions of the extensions, but was introduced at a later time via updates.
</p>

<p>
	 
</p>

<p>
	Google’s auto-update system silently deploys the newest versions to users without requiring any user approval or interaction.
</p>

<p>
	 
</p>

<p>
	Given that some of these extensions were safe for years, it is possible that they were hijacked/compromised by external actors who introduced the malicious code.
</p>

<p>
	 
</p>

<p>
	BleepingComputer contacted several publishers to inquire about this possibility, but we have not yet heard back from any of them.
</p>

<p>
	 
</p>

<p>
	Before publishing this article, Koi Security researchers <a href="https://medium.com/@idandrd/fb4ed4f40ff5" rel="external nofollow" target="_blank">discovered</a> that cybercriminals have also planted malicious extensions in the official store for Microsoft Edge, which shows a total count of 600,000 downloads.
</p>

<p>
	 
</p>

<p>
	"Combined, these eighteen extensions have infected over 2.3 million users across both browsers, creating one of the largest browser hijacking operations we’ve documented," the researchers say.
</p>

<p>
	 
</p>

<p>
	They recommend users remove all listed extensions immediately, clear the browsing data to purge any tracking identifiers, check the system for malware, and monitor accounts for suspicious activity. 
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/malicious-chrome-extensions-with-17m-installs-found-on-web-store/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30112</guid><pubDate>Tue, 08 Jul 2025 17:17:57 +0000</pubDate></item><item><title>Unless users take action, Android will let Gemini access third-party apps</title><link>https://nsaneforums.com/news/security-privacy-news/unless-users-take-action-android-will-let-gemini-access-third-party-apps-r30100/</link><description><![CDATA[<h3>
	Important changes to Android devices took effect starting Monday.
</h3>

<p>
	Starting today, Google is implementing a change that will enable its Gemini AI engine to interact with third-party apps, such as WhatsApp, even when users previously configured their devices to block such interactions. Users who don't want their previous settings to be overridden may have to take action.
</p>

<p>
	 
</p>

<p>
	An email Google sent recently informing users of the change linked to a <a href="https://support.google.com/gemini/answer/13594961?hl=en&amp;visit_id=638842317183560022-880737628&amp;p=e_live_data&amp;rd=1#extensions" rel="external nofollow">notification page</a> that said that “human reviewers (including service providers) read, annotate, and process” the data Gemini accesses. The email provides no useful guidance for preventing the changes from taking effect. The email said users can block the apps that Gemini interacts with, but even in those cases, data is stored for 72 hours.
</p>

<figure class="ars-wp-img-shortcode id-2104592 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="android-gemini-email-notification-1024x9" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/07/android-gemini-email-notification-1024x930.jpg">
				<div class="pswp-caption-content" id="caption-2104592">
					<em>An email Google recently sent to Android users. </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<h2>
	No, Google, it’s <em>not</em> good news
</h2>

<p>
	The email never explains how users can fully extricate Gemini from their Android devices and seems to contradict itself on how or whether this is even possible. At one point, it says the changes “will automatically start rolling out” today and will give Gemini access to apps such as WhatsApp, Messages, and Phone “whether your Gemini apps activity is on or off.” A few sentences later, the email says, “If you have already turned these features off, they will remain off.” Nowhere in the email or the support pages it links to are Android users informed how to remove Gemini integrations completely.
</p>

<p>
	 
</p>

<p>
	Compounding the confusion, one of the linked <a href="https://support.google.com/gemini/answer/13278892?hl=en&amp;co=GENIE.Platform%3DAndroid#zippy=%2Cin-the-gemini-mobile-app" rel="external nofollow">support pages</a> requires users to open a <a href="https://support.google.com/gemini/answer/13278668?sjid=18416362331108297465-NC" rel="external nofollow">separate support page</a> to learn how to control their Gemini app settings. Following the directions from a computer browser, I accessed the <a href="https://gemini.google.com/u/1/apps" rel="external nofollow">settings</a> of my account’s Gemini app. I was reassured to see the text indicating no activity has been stored because I have Gemini turned off. Then again, the page also said that Gemini was “not saving activity beyond 72 hours.”
</p>

<figure class="ars-wp-img-shortcode id-2104596 align-">
	<div>
		<a href="https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity.jpg" rel="external nofollow"><img alt="gemini-apps-activity-1024x648.jpg" class="large" decoding="async" height="648" loading="lazy" sizes="auto, (max-width: 1024px) 100vw, 1024px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-1024x648.jpg 1024w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-640x405.jpg 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-768x486.jpg 768w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-1536x973.jpg 1536w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-980x621.jpg 980w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-1440x912.jpg 1440w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity.jpg 1696w" width="1024" src="https://cdn.arstechnica.net/wp-content/uploads/2025/07/gemini-apps-activity-1024x648.jpg"> </a>
	</div>
</figure>

<p>
	I got similarly tripped up while trying to follow the guidance on my Pixel 7. Google support said to access the mobile Gemini app from my device. I tried, but the app was nowhere to be found.
</p>

<p>
	 
</p>

<p>
	Nowhere in the email or any of the Support pages did Google say how to remove all Gemini integrations from my phone. All of this left me wondering: Was Gemini completely disabled or not? When I discussed the <a href="https://infosec.exchange/@dangoodin/114790267037917736" rel="external nofollow">lack of clarity</a> on Mastodon, I quickly learned I wasn't the only one asking this question.
</p>

<p>
	 
</p>

<p>
	I then emailed Google PR and included a link to the Mastodon thread. I asked if someone could provide actionable guidance for my readers who want to ensure Gemini integrations are completely disabled. Instead of answering the question, the person responding to my email wrote, in part: “This update is good for users: they can now use Gemini to complete daily tasks on their mobile devices like send messages, initiate phone calls, and set timers while Gemini Apps Activity is turned off. With Gemini Apps Activity turned off, their Gemini chats are not being reviewed or used to improve our AI models.” The representative included a link to one of the same unclear support pages mentioned above.
</p>

<p>
	 
</p>

<p>
	A researcher at Tuta, a cloud-based provider of a privacy-focused email and calendar service, on Monday attempted to fill the void of actionable guidance. The immediate takeaway seems to be that Google may be bolting Gemini into Android in much the way Microsoft did with Internet Explorer into Windows, a move that landed the software maker in a protracted antitrust suit with the federal government and a dozen states, commonwealths, or districts in the late 1990s.
</p>

<p>
	 
</p>

<p>
	The Tuta post says disabling Gemini app activity is likely to prevent data collection beyond the activity temporarily stored for 72 hours. It goes on to say that if the Gemini app isn't installed already, it will not be installed after the change takes effect. That likely means my phone is safe, since Gemini isn't installed. I'm not sure if the absence of Gemini from my device is the result of me manually removing the app at some point and forgetting I had done so, or if, for some reason, it was never installed in the first place.
</p>

<p>
	 
</p>

<p>
	The Tuta post goes on to say that another remedy is to completely uninstall Gemini from the device. Of course, Google doesn't make this easy for people who aren't comfortable mucking around with a command-line terminal and making under-the-hood changes to their Android settings. This can be done by using the Android debug bridge that Google makes available to developers. Once it's installed (not easy for the faint of heart), users must uninstall the app by entering the <code>adb shell pm uninstall com.google.android.apps.bard</code> command. When I tried this, the operating system returned a message saying <code>Failure [DELETE_FAILED_INTERNAL_ERROR</code>. I'm not sure if that means the package can't be removed or it was never on my Pixel in the first place.
</p>

<p>
	 
</p>

<p>
	Google is no doubt correct in saying that many Android users will find Gemini integrations useful. Google marketers may claim the integration is good news, and for these users, this is likely to be true. A significant number of others, however, don't want Gemini or other AI engines anywhere near their devices. For the time being, these users are being left completely in the dark.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/07/unless-users-take-action-android-will-let-gemini-access-third-party-apps/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30100</guid><pubDate>Tue, 08 Jul 2025 05:30:37 +0000</pubDate></item><item><title><![CDATA[“No honor among thieves”: M&S hacking group starts turf war]]></title><link>https://nsaneforums.com/news/security-privacy-news/%E2%80%9Cno-honor-among-thieves%E2%80%9D-ms-hacking-group-starts-turf-war-r30099/</link><description><![CDATA[<h3>
	A clash between criminal ransomware groups could result in victims being extorted twice.
</h3>

<p>
	The ransomware group linked to the recent cyberattacks on UK retailers Marks and Spencer, Harrods, and the Co-Op has begun a turf war with its rivals, triggering a battle within the industry that could bring more hacks and further fallout for corporate victims.
</p>

<p>
	 
</p>

<p>
	DragonForce, a group of largely Russian-speaking cyber criminals behind a spate of high-profile attacks this year, has clashed with one of its biggest competitors RansomHub, according to cybersecurity experts tracking the battle to dominate the booming criminal ransomware sector.
</p>

<p>
	 
</p>

<p>
	They warn that the conflict between the two groups, which operate in the ransomware-as-a-service (RaaS) market, could increase risks for companies, including the potential of being extorted twice.
</p>

<p>
	 
</p>

<p>
	Toby Lewis, global head of threat analysis at Darktrace, said there was “no honor among thieves” in the hacking world.
</p>

<p>
	 
</p>

<p>
	“Most cybercrime groups have an ingrained need for kudos and one-upmanship that could lead them to attempt to ‘outcompete’ each other by trying to attack and extort the same target,” he added.
</p>

<p>
	 
</p>

<p>
	RaaS gangs function by selling the tools and infrastructure needed to access the internal systems of companies and extort them for money. They operate on the dark web where they battle to sell services to those seeking to commit cybercrime, known as “affiliates,” such as Scattered Spider, which has been linked to the M&amp;S attack and last week’s hack on Australian airline Qantas.
</p>

<p>
	 
</p>

<p>
	The relationship between DragonForce and RansomHub soured after the former rebranded itself as a “cartel” in March, which widened the services it offered and expanded its reach to attract more affiliate partners.
</p>

<p>
	 
</p>

<p>
	In the same month, RansomHub’s site was taken down with a marker left stating “R.I.P 3/3/25”, believed to be a hostile takeover by DragonForce, according to cybersecurity group Sophos. In retaliation, a RansomHub member defaced DragonForce’s site, labelling them “traitors.”
</p>

<p>
	 
</p>

<p>
	Genevieve Stark, head of cybercrime analysis at Google Threat Intelligence Group, said DragonForce could be attempting to attract RansomHub’s affiliates. The hacking group is also believed to be behind attacks on the pages of other rivals, including BlackLock and Mamona, according to Sophos.
</p>

<p>
	 
</p>

<p>
	Stark warned that whatever the motive, the fallout brings with it an increased risk of cyberattacks. “Instability within the extortion ecosystem can have serious implications for ransomware and data theft extortion victims,” she said.
</p>

<p>
	 
</p>

<p>
	While double extortions remain rare, US company UnitedHealth Group was the victim of one last year due to a fallout between hacking groups.
</p>

<p>
	 
</p>

<p>
	In that case, RansomHub was approached by affiliate hacker group, Notchy, to try to extort a second ransom payment after an initial $22 million fee was stolen by Notchy’s original RaaS partner, which faked its disappearance in order to avoid splitting the proceeds, according to cybersecurity experts.
</p>

<p>
	 
</p>

<p>
	A person familiar with the UnitedHealth hack said multiple extortion attempts were commonplace in cyberattacks, but that follow-up attempts were often opportunistic and lacked credibility.
</p>

<p>
	 
</p>

<p>
	Rafe Pilling, director of threat intelligence at Sophos, said in a worst-case scenario, the conflict between DragonForce and RansomHub could see them both target the same victim in a battle for business.
</p>

<p>
	 
</p>

<p>
	“Cybercriminals are a ruthless bunch, and a betrayal between partners can result in a situation where the victim gets extorted twice,” he added.
</p>

<p>
	 
</p>

<p>
	The global cost of cybercrime is estimated to reach $10 trillion in 2025, according to Cybersecurity Ventures. The figure—which is up from $3 trillion in 2015—comes as hacker groups have increasingly looked to maximise profit through their attacks.
</p>

<p>
	 
</p>

<p>
	DragonForce, which was first identified in August 2023, listed a total of 82 victims on its dark-web site in the following 12 months, according to cybersecurity firm Group-IB, while RansomHub—which also came to prominence in 2023—reported about 500 victims on its site in 2024.
</p>

<p>
	 
</p>

<p>
	Jake Moore, global cybersecurity adviser at ESET, warned that the volatility of the situation could make companies’ defence and response tactics more vulnerable.
</p>

<p>
	 
</p>

<p>
	“Remember this is a Wild West, lawless environment where normal competition rules simply do not apply,” he said.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/07/no-honor-among-thieves-ms-hacking-group-starts-turf-war/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30099</guid><pubDate>Tue, 08 Jul 2025 05:29:25 +0000</pubDate></item><item><title>Ingram Micro outage caused by SafePay ransomware attack</title><link>https://nsaneforums.com/news/security-privacy-news/ingram-micro-outage-caused-by-safepay-ransomware-attack-r30063/</link><description><![CDATA[<p>
	An ongoing outage at IT giant Ingram Micro is caused by a SafePay ransomware attack that led to the shutdown of internal systems, BleepingComputer has learned.
</p>

<p>
	 
</p>

<p>
	Ingram Micro is one of the world's largest business-to-business technology distributors and service providers, offering a range of solutions including hardware, software, cloud services, logistics, and training to resellers and managed service providers worldwide.
</p>

<p>
	 
</p>

<p>
	Since Thursday, Ingram Micro's website and online ordering systems <a href="https://www.bleepingcomputer.com/news/security/ingram-micro-suffers-global-outage-as-internal-systems-inaccessible/" rel="external nofollow" target="_blank">have been down</a>, with the company not disclosing the cause of the issues.
</p>

<p>
	 
</p>

<p>
	BleepingComputer has now learned that the outages are caused by a cyberattack that occurred early Thursday morning, with employees suddenly finding ransom notes created on their devices.
</p>

<p>
	 
</p>

<p>
	The ransom note, seen by BleepingComputer, is associated with the SafePay ransomware operation, which has become one of the more active operations in 2025. It is unclear if devices were actually encrypted in the attack.
</p>

<p>
	 
</p>

<p>
	It should be noted that while the ransom note claims to have stolen a wide variety of information, this is generic language used in all SafePay ransom notes and may not be true for the Ingram Micro attack.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="ransom-note-redacted~2.jpg" class="ipsImage" height="366" width="720" src="https://www.bleepstatic.com/images/news/u/1100723/ransom-note-redacted~2.jpg">
		<figcaption>
			<em>SafePay ransom note found on Ingram Micro devices<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p class="bc_quote">
	Do you have information about this or another cyberattack? If you want to share the information, you can contact us securely and confidentially on Signal at LawrenceA.11, via email at lawrence.abrams@bleepingcomputer.com, or by using our <a href="https://www.bleepingcomputer.com/news-tip/" rel="external nofollow" target="_blank">tips form</a>.
</p>

<p>
	Sources have told BleepingComputer that it is believed the threat actors breached Ingram Micro through its GlobalProtect VPN platform.
</p>

<p>
	 
</p>

<p>
	Once the attack was discovered, employees in some locations were told to work from home. The company also shut down internal systems, telling employees not to use the company's GlobalProtect VPN access, which was said to be impacted by the IT outage.
</p>

<p>
	 
</p>

<p>
	Systems that are impacted in many locations include the company's AI-powered Xvantage distribution platform and the Impulse license provisioning platform. However, BleepingComputer was told that other internal services, such as Microsoft 365, Teams, and SharePoint, continue to operate as usual.
</p>

<p>
	 
</p>

<p>
	As of yesterday, Ingram Micro has not disclosed the attack publicly or to its employees, only stating there are ongoing IT issues, as indicated by company-wide advisories shared with BleepingComputer.
</p>

<p>
	 
</p>

<p>
	The SafePay ransomware gang is a relatively new operation that was first seen in November 2024, accumulating over 220 victims since then.
</p>

<p>
	 
</p>

<p>
	The ransomware operation has been previously observed breaching corporate networks <a href="https://www.huntress.com/blog/its-not-safe-to-pay-safepay" rel="external nofollow" target="_blank">through VPN gateways</a> using <a href="https://www.nccgroup.com/us/research-blog/weak-passwords-led-to-safepay-ransomware-yet-again/" rel="external nofollow" target="_blank">compromised credentials</a> and <a href="https://medium.com/@DCSO_CyTec/safepay-the-new-kid-on-the-block-4141188a626d" rel="external nofollow" target="_blank">password spray attacks</a>.
</p>

<p>
	 
</p>

<p>
	BleepingComputer contacted Ingram Micro yesterday and today about the outages and ransomware attack, but did not receive a response to our emails.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/ingram-micro-outage-caused-by-safepay-ransomware-attack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30063</guid><pubDate>Sat, 05 Jul 2025 20:52:14 +0000</pubDate></item><item><title>WhatsApp is getting ads. What it means for you and your privacy</title><link>https://nsaneforums.com/news/security-privacy-news/whatsapp-is-getting-ads-what-it-means-for-you-and-your-privacy-r30049/</link><description><![CDATA[<p>
	WhatsApp, an instant messaging app that Meta bought in 2014, is getting ads. Meta<span> </span><a href="https://blog.whatsapp.com/helping-you-find-more-channels-and-businesses-on-whatsapp" rel="external nofollow">confirmed after years of speculation</a>.
</p>

<p>
	 
</p>

<p>
	All other major Meta services have already been inundated with a steady stream of ads — think Instagram, Facebook Messenger, and the latest addition to the Meta family, Threads, which got ads not long after its birth. So, the fact that WhatsApp still didn’t have ads as of 2025 felt like an oddity — something that ran counter to Meta’s entire ad-driven business model.
</p>

<p>
	 
</p>

<p>
	And, although the eventual arrival of ads in WhatsApp was a long time coming and is in line with what Meta has been doing before, we can't help but regret this development.
</p>

<h2 id="where-will-the-ads-be">
	Where will the ads be?
</h2>

<p>
	In its announcement, Meta said that WhatsApp will be getting ads in just one tab —<span> </span><em>Updates</em>, which combines<span> </span><em>Status</em><span> </span>and<span> </span><em>Channels</em>.<span> </span><em>Status</em><span> </span>is the tab designed for posting Status updates, similar to Instagram or Telegram Stories. While it may not be generating as much buzz as its Instagram lookalike (probably because it is mostly reserved to sharing content with close contacts), according to WhatsApp itself, the<span> </span><em>Updates</em><span> </span>tab is used by 1.5 billion people daily across the globe.
</p>

<p>
	 
</p>

<p>
	The ads will appear in several places, but perhaps the most potentially annoying slot is among the status updates posted by your family and friends.
</p>

<p>
	 
</p>

<p>
	<img alt="ads_status.png" data-ratio="74.21" loading="lazy" width="667" src="https://cdn.adtidy.org/blog/new/kjvhaads_status.png?mw=1360">
</p>

<p>
	 
</p>

<p>
	Source: WhatsApp
</p>

<p>
	 
</p>

<p>
	The ads will also sneak into the Channels section. Channels are a one-way broadcasting feature that lets people follow posts from individuals or organizations they're interested in. Now, if you want to explore channels you might like, the promoted ones will appear at the top of the selection.
</p>

<p>
	 
</p>

<p>
	<img alt="promoted_channels.png" data-ratio="75.10" loading="lazy" width="719" src="https://cdn.adtidy.org/blog/new/72z84promoted_channels.png?mw=1360">
</p>

<h2 id="how-bad-is-it-for-privacy">
	How bad is it for privacy?
</h2>

<p>
	The first question that comes to mind for privacy-conscious users is what data WhatsApp will use to target ads and whether it’s possible to opt out.
</p>

<p>
	 
</p>

<p>
	When it comes to data collection, WhatsApp claims it will use<span> </span><em>“limited info”</em><span> </span>— such as your country, city, language, the channels you follow, and how you interact with the ads. If you’ve chosen to integrate WhatsApp with Meta’s Accounts Center, then the app will not just stop at your basic location or interests.
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		If you've ever logged into WhatsApp using your Facebook or Instagram account, or if you've linked your WhatsApp account to your Facebook profile, you're essentially integrating WhatsApp with Meta’s Accounts Center.
	</p>
</blockquote>

<p>
	 
</p>

<p>
	This means that WhatsApp could also tap into your ad preferences and behavioral data across the Meta ecosystem, enabling the company to serve even more targeted ads.
</p>

<p>
	 
</p>

<p>
	As for the possibility to opt out, there is none. Not even for money. Unlike Telegram, which places ads in public channels but offers the option to buy Telegram Premium for an ad-free experience, WhatsApp doesn’t have any of this — yet, or maybe forever.
</p>

<h2 id="can-these-ads-be-blocked">
	Can these ads be blocked?
</h2>

<p>
	When it comes to blocking WhatsApp's new ads, it’s not completely unfeasible, but it's more complex than it may seem, especially on mobile.
</p>

<p>
	 
</p>

<p>
	On the web, there’s a better chance of blocking these ads. Put simply, if you use a browser-based version of WhatsApp on your computer, it will most likely be possible to filter out the ads using AdGuard or any other ad-blocking solution. However, things get way less clear-cut when using WhatsApp on your phone.
</p>

<p>
	 
</p>

<p>
	The reason for this is that, much like with other Meta platforms, these ads will likely be delivered through special domains used for both advertising and other content. In theory, it still makes it possible to block them, but in practice, it’s a long shot. Unlike web-browsing environments, mobile platforms such as iOS and Android make it far more challenging to intercept traffic at a granular level. With mobile apps, the traffic is typically encrypted via HTTPS, which complicates matters since it's not possible to easily decrypt or analyze this traffic. While it may be possible to route the traffic through certain proxies, the lack of decryption often means that the payload—i.e., the ads—remain hidden from the filter.
</p>

<p>
	 
</p>

<p>
	As an ad blocker, you would need to continuously analyze the app’s traffic to ensure that new ad delivery mechanisms don’t slip through the filters. However, without full access to the encrypted content, even the most advanced filtering solutions can only block a portion of the ads. In short, while blocking WhatsApp’s is possible on the web, it’s highly unlikely to work effectively on mobile devices due to the constraints of iOS and Android operating systems, which are designed to prevent such interception of traffic.
</p>

<h2 id="final-thoughts">
	Final thoughts
</h2>

<p>
	WhatsApp says that it’s rolling out ads with your privacy in mind, meaning it won’t harvest data from your private conversations or use information from your private statuses, phone calls, or the groups you’re in to target ads to you.<span> </span><em>“Your personal messages, calls, and statuses remain end-to-end encrypted, meaning no one (not even us) can see or hear them,”</em><span> </span>WhatsApp says.
</p>

<p>
	 
</p>

<p>
	Likewise, the fact that WhatsApp will<span> </span><em>only</em><span> </span>place ads in two places (for now) might sound like no big deal — something we can live with.
</p>

<p>
	 
</p>

<p>
	The thing is, though, this might just be the beginning. While the new ad experience doesn’t sound too intrusive (at least on paper), it could turn out to be. Moreover, Meta may decide to place ads in more places over time, with the current update serving as a trial run.
</p>

<p>
	 
</p>

<p>
	<a href="https://adguard.com/en/blog/whatsapp-getting-ads.html" rel="external nofollow">Source</a>
</p>
]]></description><guid isPermaLink="false">30049</guid><pubDate>Fri, 04 Jul 2025 15:06:00 +0000</pubDate></item><item><title>Hunters International ransomware shuts down, releases free decryptors</title><link>https://nsaneforums.com/news/security-privacy-news/hunters-international-ransomware-shuts-down-releases-free-decryptors-r30031/</link><description><![CDATA[<p>
	The Hunters International Ransomware-as-a-Service (RaaS) operation announced today that it has officially closed down its operations and will offer free decryptors to help victims recover their data without paying a ransom.
</p>

<p>
	 
</p>

<p>
	"After careful consideration and in light of recent developments, we have decided to close the Hunters International project. This decision was not made lightly, and we recognize the impact it has on the organizations we have interacted with," the cybercrime gang says in a statement published on its dark web leak earlier today.
</p>

<p>
	 
</p>

<p>
	"As a gesture of goodwill and to assist those affected by our previous activities, we are offering free decryption software to all companies that have been impacted by our ransomware. Our goal is to ensure that you can recover your encrypted data without the burden of paying ransoms."
</p>

<p>
	 
</p>

<p>
	The threat actors also removed all entries from the extortion portal and added that companies whose systems were encrypted in Hunters International ransomware attacks can request decryption tools and recovery guidance on the gang's official website.
</p>

<p>
	 
</p>

<p>
	While the ransomware group doesn't explain what "recent developments" it refers to, today's announcement follows a November 17 statement saying that Hunters International will soon shut down because of increased law enforcement scrutiny and declining profitability.
</p>

<p>
	 
</p>

<p>
	Threat intelligence firm Group-IB also <a href="https://www.bleepingcomputer.com/news/security/hunters-international-rebrands-as-world-leaks-in-shift-to-data-extortion/" rel="external nofollow" target="_blank">revealed in April</a> that Hunters International was rebranding with plans to focus on data theft and extortion-only attacks, and had launched a new extortion-only operation known as "World Leaks."
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Hunters International shutdown announcement" class="ipsImage" height="263" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Hunters%20International%20shutdown%20announcement.png">
		<figcaption>
			<em>Hunters International shutdown announcement (BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<p>
	"Unlike Hunters International, which combined encryption with extortion, World Leaks operates as an extortion-only group using a custom-built exfiltration tool," Group-IB said at the time, adding that the new tool appears to be an upgraded version of the Storage Software exfiltration tool used by Hunters International's ransomware affiliates.
</p>

<p>
	 
</p>

<p>
	Hunters International emerged in late 2023 and was flagged by security researchers and ransomware experts as a <a href="https://www.bleepingcomputer.com/news/security/new-hunters-international-ransomware-possible-rebrand-of-hive/" rel="external nofollow" target="_blank">potential rebrand of Hive</a> due to code similarities. The ransomware group's malware targets a wide range of platforms, including Windows, Linux, FreeBSD, SunOS, and ESXi (VMware servers), and it also comes with support for x64, x86, and ARM architectures.
</p>

<p>
	 
</p>

<p>
	Over the last two years, Hunters International has targeted companies of all sizes, with ransom demands ranging from hundreds of thousands to millions of dollars, depending on the size of the breached organization.
</p>

<p>
	 
</p>

<p>
	The ransomware gang has claimed responsibility for almost 300 attacks worldwide, making it one of the most active ransomware operations in recent years.
</p>

<p>
	 
</p>

<p>
	Notable victims claimed by Hunters International include the <a href="https://www.bleepingcomputer.com/news/security/us-marshals-service-disputes-ransomware-gangs-breach-claims/" rel="external nofollow" target="_blank">U.S. Marshals Service</a>, Japanese optics giant <a href="https://www.bleepingcomputer.com/news/security/optics-giant-hoya-hit-with-10-million-ransomware-demand/" rel="external nofollow" target="_blank">Hoya</a>, <a href="https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-claims-attack-on-tata-technologies/" rel="external nofollow" target="_blank">Tata Technologies</a>, North American automobile dealership <a href="https://www.bleepingcomputer.com/news/security/autocanada-says-ransomware-attack-may-impact-employee-data/" rel="external nofollow" target="_blank">AutoCanada</a>, U.S. Navy contractor <a href="https://www.bleepingcomputer.com/news/security/navy-contractor-austal-usa-confirms-cyberattack-after-data-leak/" rel="external nofollow" target="_blank">Austal USA</a>, and <a href="https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/" rel="external nofollow" target="_blank">Integris Health</a>, Oklahoma's largest not-for-profit healthcare network.
</p>

<p>
	 
</p>

<p>
	In December 2024, Hunters International also hacked the <a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-behind-threats-to-fred-hutch-cancer-patients/" rel="external nofollow" target="_blank">Fred Hutch Cancer Center</a>, threatening to leak the stolen data of over 800,000 cancer patients if they were not paid.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-shuts-down-after-world-leaks-rebrand/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30031</guid><pubDate>Thu, 03 Jul 2025 17:49:12 +0000</pubDate></item><item><title>A 13-year-old prodigy helped improve the security of Microsoft products</title><link>https://nsaneforums.com/news/security-privacy-news/a-13-year-old-prodigy-helped-improve-the-security-of-microsoft-products-r30015/</link><description><![CDATA[<p>
	<a automate_uuid="0e968164-e0ae-4ee7-87fe-5f6bcc561cc0" href="https://www.neowin.net/news/tags/cybersecurity/" rel="external nofollow">Cybersecurity</a> is a particularly important avenue for any firm, especially those in tech. It's even more critical for companies like Microsoft, which is not only responsible for managing its security infrastructure, but also the <a automate_uuid="797cd6cf-f74a-4a52-97cf-5ad6b793342f" href="https://www.neowin.net/news/it-admins-should-check-these-new-settings-in-edge-138-before-they-are-enabled-by-default/" rel="external nofollow">security posture of its clients</a> and <a automate_uuid="149030ff-6468-4401-9395-be201f17d42a" href="https://www.neowin.net/news/microsoft-no-we-havent-lost-400-million-windows-customers/" rel="external nofollow">over a billion customers</a>. The Redmond firm has a dedicated Microsoft Security Response Team (MSRC) that works with researchers all over the globe to identify security vulnerabilities in products made by the company and then collaborate with relevant teams to patch those issues.
</p>

<p>
	 
</p>

<p>
	Interestingly, MSRC partnered with a 13-year-old, identified as "Dylan", a few years ago, and has been working with him to fix vulnerabilities across various products. In terms of background, Dylan has worked with technical tools and languages from a very young age. Starting from Scratch, the teenager eventually familiarized himself with HTML and other programming languages and began analyzing the source code of educational platforms.
</p>

<p>
	 
</p>

<p>
	Dylan's first foray into the world of professional cybersecurity was when his school disabled the ability for students to create chats in Microsoft Teams during the COVID-19 pandemic. After nine months of research and development, along with trial and error, Dylan discovered a vulnerability that allowed him to take over any Teams group. The teenager promptly reported this security hole to Microsoft, which actually had to update the terms and conditions of its Bug Bounty Program to enable people as young as 13 to participate.
</p>

<p>
	 
</p>

<p>
	Since then, Dylan has been working directly with MSRC to discover other vulnerabilities, too. The ethical hacker reported a security vulnerability in the Authenticator Broker service, too. He is known for his articulate communication skills and for not staying silent when he disagrees with MSRC's initial assessments.
</p>

<p>
	 
</p>

<p>
	The prodigy, who was also MSRC's youngest researcher, is now a junior in high school. He submitted 20 vulnerabilities reports last summer alone, which is impressive considering that he had only submitted six in total before that. You can <a automate_uuid="c43d2139-6307-4f22-89cb-972c629d8402" href="https://msrc.microsoft.com/blog/2025/07/rising-star-meet-dylan-msrcs-youngest-security-researcher/" rel="external nofollow">read more about Dylan's journey here</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/a-13-year-old-prodigy-helped-improve-the-security-of-microsoft-products/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30015</guid><pubDate>Wed, 02 Jul 2025 20:27:37 +0000</pubDate></item><item><title>Dozens of fake wallet add-ons flood Firefox store to drain crypto</title><link>https://nsaneforums.com/news/security-privacy-news/dozens-of-fake-wallet-add-ons-flood-firefox-store-to-drain-crypto-r30014/</link><description><![CDATA[<p>
	More than 40 fake extensions in Firefox’s official add-ons store are impersonating popular cryptocurrency wallets from trusted providers to steal wallet credentials and sensitive data.
</p>

<p>
	 
</p>

<p>
	Some of the extensions pretend to be wallets from Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero, and include malicious code that sends stolen information to attacker-controlled servers.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Fake wallet extensions" class="ipsImage" height="408" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/June/ext2.jpg">
		<figcaption>
			<em>Fake wallet extensions on the Firefox add-ons store<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	Researchers at Koi security found the risky extensions along with evidence indicating that behind the campaign is a Russian-speaking threat group.
</p>

<p>
	 
</p>

<p>
	In a <a href="https://blog.koi.security/foxywallet-40-malicious-firefox-extensions-exposed-4c14419de486" rel="external nofollow" target="_blank">report</a> shared with BleepingComputer, the researchers say that many of these browser add-ons are clones of open-source versions of legitimate wallets with added malicious logic.
</p>

<p>
	 
</p>

<p>
	Koi security presents examples of ‘input’ and ‘click’ event listeners in the code, which monitor for sensitive data inputs from the victim.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Malicious code snippets in the extensions" class="ipsImage" height="204" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/June/1.jpg">
		<figcaption>
			<em>Malicious code snippets in the extensions<br>
			Source: Koi Security</em>
		</figcaption>
	</figure>
</div>

<p>
	The code checks for input strings that are longer than 30 characters to filter for realistic wallet keys/seed phrases, and exfiltrates the data to the attackers.
</p>

<p>
	 
</p>

<p>
	Error dialogs are hidden from the user by setting the opacity to zero for any elements that might alert the user of the activity.
</p>

<p>
	 
</p>

<p>
	Seed phrases (recovery/mnemonic phrase) are master keys typically comprising multiple words, allowing users to recover or port wallets to new devices.
</p>

<p>
	 
</p>

<p>
	Obtaining someone’s seed phrase makes it possible to steal all the cryptocurrency assets in the wallet. The theft appears as a legitimate transaction and is irreversible.
</p>

<p>
	 
</p>

<p>
	The campaign has been active since at least April and new extensions appear to be added to the Firefox store constantly. The researchers say that the newest malicious entries are as recent as last week.
</p>

<p>
	 
</p>

<p>
	To build trust, the threat actors use the real logos of the brands they impersonate while many of the extensions have hundreds of fake five-star reviews. Some of them also have a large number of one-star reviews reporting the scam, likely from users that lost their cryptocurrency.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Fake Metamask extensions" class="ipsImage" height="600" style="height: auto;" width="1103" src="https://www.bleepstatic.com/images/news/u/1220909/2025/June/ext.jpg">
		<figcaption>
			<em>Fake Metamask extensions on the Firefox store<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	Although most of the user reviews are obviously fake (they surpass the installation figure by far), many users not paying attention to the details could still be tricked into installing them and risk their seed phrases being stolen.
</p>

<p>
	 
</p>

<p>
	Mozilla has developed an early <a href="https://www.bleepingcomputer.com/news/security/mozilla-launches-new-system-to-detect-firefox-crypto-drainer-add-ons/" rel="external nofollow" target="_blank">detection system for crypto scam extensions</a>. It relies on automated indicators for assessing the risk level. If a threshold is reached, human reviewers analyze the submission and block it if it's malicious.
</p>

<p>
	 
</p>

<p>
	Koi Security told BleepingComputer that they reported the findings to the Firefox store using the official reporting tool, but the fake extensions continue to be available at the time of writing.
</p>

<p>
	 
</p>

<p>
	BleepingComputer has reached out to Mozilla for a comment on the matter but a statement wasn’t immediately available.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/dozens-of-fake-wallet-add-ons-flood-firefox-store-to-drain-crypto/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30014</guid><pubDate>Wed, 02 Jul 2025 20:26:49 +0000</pubDate></item><item><title>Microsoft: DNS issue blocks delivery of Exchange Online OTP codes</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-dns-issue-blocks-delivery-of-exchange-online-otp-codes-r30013/</link><description><![CDATA[<p>
	Microsoft is working to fix a DNS misconfiguration that is causing one-time passcode (OTP) message delivery failures in Exchange Online for some users.
</p>

<p>
	 
</p>

<p>
	Recipients <a href="https://support.microsoft.com/en-us/office/open-encrypted-and-protected-messages-1157a286-8ecc-4b1e-ac43-2a608fbf3098#bkmk_openprotected" rel="external nofollow" target="_blank">may receive</a> a single-use access code via a separate email to open an encrypted message in Gmail, Yahoo, or other email clients without a Microsoft 365 subscription. This OTP message allows them to view the encrypted email on the Office 365 Message Encryption portal.
</p>

<p>
	 
</p>

<p>
	However, as the company explains in a new <a href="https://admin.microsoft.com/Adminportal/Home?#/homepage/:/alerts/EX1107369" rel="external nofollow" target="_blank">service alert</a> published in the admin center, some users may not receive OTP emails because of a known Domain Name System (DNS) record misconfiguration.
</p>

<p>
	 
</p>

<p>
	"Some users expecting to receive OTP email messages for encrypted email messages in Exchange Online may be impacted," Microsoft said.
</p>

<p>
	 
</p>

<p>
	"DNS records for the domain that provides OTP email messages to encrypted messages became misconfigured, which is causing impact. We've corrected the DNS record configurations for the affected domain and are reaching out to a sample of affected users to confirm whether the impact is remediated."
</p>

<p>
	 
</p>

<p>
	In a previous update regarding this incident, Microsoft noted that the OTP delivery problems are due to the removal of DNS records for the domain that generates access codes for encrypted messages.
</p>

<p>
	 
</p>

<p>
	It also added that the known issue specifically affects users who have a process set up to perform DNS checks on incoming email messages.
</p>

<p>
	 
</p>

<p>
	While Microsoft has yet to provide detailed information about the extent of the incident, the company has identified it as a critical service issue in the Microsoft 365 admin center, indicating that it has a significant impact on users.
</p>

<p>
	 
</p>

<p>
	In February, Microsoft resolved a <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-entra-id-authentication-issue-caused-by-dns-change/" rel="external nofollow" target="_blank">widespread issue causing Entra ID DNS authentication failures</a>, which were triggered by a DNS change that resulted in DNS resolution failures for the autologon.microsoftazuread.sso.com domain.
</p>

<p>
	 
</p>

<p>
	In recent years, Microsoft has had to address outages and incidents caused by DNS issues, including one in August 2023 that was triggered by a misconfigured DNS SPF record, resulting in worldwide <a href="https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/" rel="external nofollow" target="_blank">Hotmail email delivery failures</a>.
</p>

<p>
	 
</p>

<p>
	Two years earlier, in April 2021, a code defect was responsible for a <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/" rel="external nofollow" target="_blank">global outage that affected many Microsoft services</a>due to overloaded Azure DNS servers.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-links-dns-issue-to-exchange-online-otp-delivery-failures/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30013</guid><pubDate>Wed, 02 Jul 2025 20:24:53 +0000</pubDate></item><item><title>Google fixes fourth actively exploited Chrome zero-day of 2025</title><link>https://nsaneforums.com/news/security-privacy-news/google-fixes-fourth-actively-exploited-chrome-zero-day-of-2025-r29998/</link><description><![CDATA[<p>
	Google has released emergency updates to patch another Chrome zero-day vulnerability exploited in attacks, marking the fourth such flaw fixed since the start of the year.
</p>

<p>
	 
</p>

<p>
	"Google is aware that an exploit for CVE-2025-6554 exists in the wild," the browser vendor said in a <a href="https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html" rel="external nofollow" target="_blank">security advisory</a>issued on Monday. "This issue was mitigated on 2025-06-26 by a configuration change pushed out to Stable channel across all platforms."
</p>

<p>
	 
</p>

<p>
	The company fixed the zero-day for users in the Stable Desktop channel, with new versions rolling out worldwide to Windows (138.0.7204.96/.97), Mac (138.0.7204.92/.93), and Linux users (138.0.7204.96) one day after the issue was reported to Google.
</p>

<p>
	 
</p>

<p>
	The bug was discovered by Clément Lecigne of Google's Threat Analysis Group (TAG), a collective of security researchers focused on defending Google customers from state-sponsored and other similar attacks.
</p>

<p>
	 
</p>

<p>
	Google TAG frequently discovers zero-day exploits deployed by government-sponsored threat actors in targeted attacks to infect high-risk individuals, including opposition politicians, dissidents, and journalists, with spyware.
</p>

<p>
	 
</p>

<p>
	Although the security updates patching CVE-2025-6554 could take days or weeks to reach all users, according to Google, they were immediately available when BleepingComputer checked for updates earlier today.
</p>

<p>
	 
</p>

<p>
	Users who prefer not to update manually can also rely on their web browser to automatically check for new updates and install them after the next launch.
</p>

<p>
	 
</p>

<p>
	<img alt="Google Chrome 138.0.7204.93" class="ipsImage" height="298" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Google%20Chrome%20138_0_7204_93.png">
</p>

<p>
	 
</p>

<p>
	The zero-day bug fixed today is a high-severity <a href="https://cwe.mitre.org/data/definitions/843.html" rel="external nofollow" target="_blank">type confusion</a> weakness in the Chrome V8 JavaScript engine. While such flaws generally lead to browser crashes after successful exploitation by reading or writing memory out of buffer bounds, attackers can also exploit them to execute arbitrary code on unpatched devices.
</p>

<p>
	 
</p>

<p>
	Even though Google stated that this vulnerability was exploited in the wild, the company has yet to share technical details or additional information regarding these attacks.
</p>

<p>
	 
</p>

<p>
	"Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," Google said.
</p>

<p>
	 
</p>

<p>
	This is the fourth actively exploited Google Chrome zero-day fixed since the start of the year, with three more patched in March, May, and June.
</p>

<p>
	 
</p>

<p>
	The first, a high-severity sandbox escape flaw (CVE-2025-2783) reported by Kaspersky's Boris Larin and Igor Kuznetsov, <a href="https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/" rel="external nofollow" target="_blank">was used in espionage attacks</a> targeting Russian government organizations and media outlets with malware.
</p>

<p>
	 
</p>

<p>
	Google released another set of emergency security updates in May to address a Chrome zero-day (CVE-2025-4664) that can allow attackers <a href="https://www.bleepingcomputer.com/news/security/google-fixes-high-severity-chrome-flaw-with-public-exploit/" rel="external nofollow" target="_blank">to hijack accounts</a>. One month later, the company <a href="https://www.bleepingcomputer.com/news/security/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/" rel="external nofollow" target="_blank">addressed an out-of-bounds read and write weakness</a> in Chrome's V8 JavaScript engine discovered by Google TAG's Benoît Sevens and Clément Lecigne.
</p>

<p>
	 
</p>

<p>
	In 2024, <a href="https://www.bleepingcomputer.com/news/security/google-tags-a-tenth-chrome-zero-day-as-exploited-this-year/" rel="external nofollow" target="_blank">Google patched a total of 10 zero-day vulnerabilities</a> that were either exploited in attacks or demoed during Pwn2Own hacking competitions.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-fixes-fourth-actively-exploited-chrome-zero-day-of-2025/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29998</guid><pubDate>Tue, 01 Jul 2025 21:53:00 +0000</pubDate></item><item><title>Cloudflare Is Blocking AI Crawlers by Default</title><link>https://nsaneforums.com/news/security-privacy-news/cloudflare-is-blocking-ai-crawlers-by-default-r29997/</link><description><![CDATA[<h3>
	The age of the AI scraping free-for-all may be coming to an end. At least if Cloudflare gets its way.
</h3>

<p>
	<span class="lead-in-text-callout">Last year, internet</span> infrastructure firm Cloudflare <a href="https://www.wired.com/story/cloudflare-tools-detect-block-ai-bots/" rel="external nofollow">launched tools</a> enabling its customers to block AI scrapers. Today the company has taken its fight against permissionless scraping several steps further. It has switched to blocking AI crawlers by default for its customers and is moving forward with a Pay Per Crawl program that lets customers charge AI companies to scrape their websites.
</p>

<p>
	 
</p>

<p>
	Web crawlers have trawled the internet for information for decades. Without them, people would lose vitally important online tools, from Google Search to the Internet Archive’s invaluable <a href="https://www.wired.com/story/internet-archive-memory-wayback-machine-lawsuits/" rel="external nofollow">digital preservation work</a>. But the AI boom has produced a corresponding boomlet in AI-focused web crawlers, and these bots scrape web pages with a frequency that can <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://techcrunch.com/2025/01/10/how-openais-bot-crushed-this-seven-person-companys-web-site-like-a-ddos-attack/" href="https://techcrunch.com/2025/01/10/how-openais-bot-crushed-this-seven-person-companys-web-site-like-a-ddos-attack/" rel="external nofollow" target="_blank">mimic a DDoS attack</a>, <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://techcrunch.com/2025/04/02/ai-crawlers-cause-wikimedia-commons-bandwidth-demands-to-surge-50/" href="https://techcrunch.com/2025/04/02/ai-crawlers-cause-wikimedia-commons-bandwidth-demands-to-surge-50/" rel="external nofollow" target="_blank">straining servers</a> and <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://www.glamelab.org/products/are-ai-bots-knocking-cultural-heritage-offline/?ref=404media.co" href="https://www.glamelab.org/products/are-ai-bots-knocking-cultural-heritage-offline/?ref=404media.co" rel="external nofollow" target="_blank">knocking websites offline</a>. Even when websites can handle the heightened activity, many <a href="https://www.wired.com/story/applebot-extended-apple-ai-scraping/" rel="external nofollow">do not want</a> AI crawlers scraping their content, especially news publications that are demanding AI companies to pay to use their work. “We’ve been feverishly trying to protect ourselves,” says Danielle Coffey, the president and CEO of the trade group News Media Alliance, which represents several thousand North American outlets.
</p>

<p>
	 
</p>

<p>
	So far, Cloudflare’s head of AI control, privacy, and media products, Will Allen, tells WIRED, over 1 million customer websites have activated its older AI-bot-blocking tools. Now millions more will have the option of keeping bot blocking as their default. Cloudflare also says it can identify even “shadow” scrapers that are not publicized by AI companies. The company noted that it uses a proprietary combination of behavioral analysis, fingerprinting, and machine learning to classify and separate AI bots from “good” bots.
</p>

<p>
	 
</p>

<p>
	A widely used web standard called the Robots Exclusion Protocol, often implemented through a robots.txt file, helps publishers block bots on a case-by-case basis, but following it is not legally required, and there’s <a href="https://www.wired.com/story/perplexity-is-a-bullshit-machine/" rel="external nofollow">plenty of evidence</a> that some AI companies try to evade efforts to block their scrapers. “Robots.txt is ignored,” Coffey says. According to <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://tollbit.com/bots/25q1/" href="https://tollbit.com/bots/25q1/" rel="external nofollow" target="_blank">a report</a> from the content licensing platform Tollbit, which offers its own marketplace for publishers to negotiate with AI companies over bot access, AI scraping is still on the rise—including scraping that ignores robots.txt. Tollbit found that over 26 million scrapes ignored the protocol in March 2025 alone.
</p>

<p>
	 
</p>

<p>
	In this context, Cloudflare’s shift to blocking by default could prove a significant roadblock to surreptitious scrapers and could give publishers more leverage to negotiate, whether through the Pay Per Crawl program or otherwise. “This could dramatically change the power dynamic. Up to this point, AI companies have not needed to pay to license content, because they've known that they can just take it without consequences,” says Atlantic CEO (and former WIRED editor in chief) Nicholas Thompson. “Now they'll have to negotiate, and it will become a competitive advantage for the AI companies that can strike more and better deals with more and better publishers.”
</p>

<p>
	 
</p>

<p>
	AI startup <a href="https://www.wired.com/story/bill-gross-prorata-generative-ai-business/" rel="external nofollow">ProRata</a>, which operates the AI search engine Gist.AI, has agreed to participate in the Pay Per Crawl program, according to CEO and founder Bill Gross. “We firmly believe that all content creators and publishers should be compensated when their content is used in AI answers,” Gross says.
</p>

<p>
	 
</p>

<p>
	Of course, it remains to be seen whether the big players in the AI space will participate in a program like Pay Per Crawl, which is in beta. (Cloudflare declined to name current participants.) Companies like OpenAI have struck <a href="https://www.wired.com/story/conde-nast-openai-deal/" rel="external nofollow">licensing deals</a> with a variety of publishing partners, including WIRED parent company Condé Nast, but specific details of these agreements have not been disclosed, including whether the agreement covers bot access.
</p>

<p>
	 
</p>

<p>
	Meanwhile, there’s an entire online ecosystem of <a href="https://www.google.com/search?q=getting+around+cloudflare+scraper+bot+blocker&amp;sca_esv=bec2fea0dbf0b6aa&amp;rlz=1C5GCEM_enUS1120US1121&amp;source=lnms&amp;sa=X&amp;ved=2ahUKEwjq-p_C6ZmOAxUH5MkDHXu8KD44ChDSlAl6BAgGEAM&amp;biw=1491&amp;bih=757&amp;dpr=2" rel="external nofollow">tutorials</a> about how to evade Cloudflare’s bot blocking tools aimed at web scrapers. As the blocking default rolls out, it’s likely these efforts will continue. Cloudflare emphasizes that customers who do want to let the robots scrape unimpeded will be able to turn off the blocking setting. “All blocking is fully optional and at the discretion of each individual user,” Allen says.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.wired.com/story/cloudflare-blocks-ai-crawlers-default/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29997</guid><pubDate>Tue, 01 Jul 2025 21:51:51 +0000</pubDate></item><item><title>Microsoft Authenticator is ending support for passwords</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-authenticator-is-ending-support-for-passwords-r29977/</link><description><![CDATA[<h3>
	Microsoft’s security app is dropping password management soon, so you’ll need to move them somewhere else or access them using Edge.
</h3>

<p>
	Microsoft will soon no longer let you use its Authenticator app to store or autofill passwords. <a href="https://support.microsoft.com/en-us/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6" rel="external nofollow">Starting in July</a>, you won’t be able to autofill saved passwords using Authenticator, and you’ll have to use Microsoft Edge or another password management solution instead.
</p>

<p>
	 
</p>

<p>
	Microsoft also plans on deleting your saved payment information in Authenticator this July before erasing passwords in August. Last month, <a href="https://www.bleepingcomputer.com/news/security/microsoft-ends-authenticator-password-autofill-moves-users-to-edge/" rel="external nofollow">Microsoft Authenticator stopped</a> accepting new passwords as part of plans to consolidate its password autofilling feature within Edge.
</p>

<p>
	 
</p>

<p>
	Microsoft will automatically sync saved passwords to your account, allowing you to access them in Edge. You can set Edge as your device’s default autofill provider by finding the option in your device’s settings and selecting Edge instead of Authenticator. If you don’t want to use Edge, make sure to export your passwords to another service by August.
</p>

<p>
	 
</p>

<p>
	Microsoft Authenticator launched as a multifactor authentication solution in 2016, and it added <a href="/2020/12/16/22178026/microsoft-authenticator-autofill-feature-password-manager" rel="">support for password storage in 2020</a>. Though Microsoft Authenticator is ending support for passwords, it will continue to support passkeys, the solution that lets you use your device’s authentication method to sign into accounts, such as a PIN, fingerprint, or face scan.
</p>

<p>
	 
</p>

<p>
	You can find more information about how to export your passwords or make Edge your default autofilling provider <a href="https://support.microsoft.com/en-us/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6#id0ebbj=android" rel="external nofollow">from Microsoft’s website</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/news/695288/microsoft-authenticator-autofill-store-passwords" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29977</guid><pubDate>Mon, 30 Jun 2025 19:39:43 +0000</pubDate></item><item><title>Bluetooth flaws could let hackers spy through your microphone</title><link>https://nsaneforums.com/news/security-privacy-news/bluetooth-flaws-could-let-hackers-spy-through-your-microphone-r29967/</link><description><![CDATA[<p>
	Vulnerabilities affecting a Bluetooth chipset present in more than two dozen audio devices from ten vendors can be exploited for eavesdropping or stealing sensitive information.
</p>

<p>
	 
</p>

<p>
	Researchers confirmed that 29 devices from Beyerdynamic, Bose, Sony, Marshall, Jabra, JBL, Jlab, EarisMax, MoerLabs, and Teufel are affected.
</p>

<p>
	 
</p>

<p>
	The list of impacted products includes speakers, earbuds, headphones, and wireless microphones.
</p>

<p>
	 
</p>

<p>
	The security problems could be leveraged to take over a vulnerable product and on some phones, an attacker within connection range may be able to extract call history and contacts.
</p>

<h3>
	Snooping over a Bluetooth connection
</h3>

<p>
	At the <a href="https://troopers.de/" rel="external nofollow" target="_blank">TROOPERS</a> security conference in Germany, researchers at cybersecurity company ERNW disclosed three vulnerabilities in the Airoha systems on a chip (SoCs), which are widely used in True Wireless Stereo (TWS) earbuds.
</p>

<p>
	 
</p>

<p>
	The issues are not critical and besides close physical proximity (Bluetooth range), their exploitation also requires “a high technical skill set.” They received the following identifiers:
</p>

<p>
	 
</p>

<ul>
	<li>
		CVE-2025-20700 (6.7, medium severity score) - missing authentication for GATT services
	</li>
	<li>
		CVE-2025-20701 (6.7, medium severity score) -  missing authentication for Bluetooth BR/EDR
	</li>
	<li>
		CVE-2025-20702 (7.5, high severity score) - critical capabilities of a custom protocol
	</li>
</ul>

<p>
	 
</p>

<p>
	ERNW researchers say they created a proof-of-concept exploit code that allowed them to read the currently playing media from the targeted headphones.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Reading currently played song from a vulnerable Airoha device" class="ipsImage" height="211" width="720" src="https://www.bleepstatic.com/images/news/u/1100723/ERNW_Airoha_song.png">
		<figcaption>
			<em>Reading currently played song from a vulnerable Airoha device<br>
			source: ERWN</em>
		</figcaption>
	</figure>
</div>

<p>
	While such an attack may not present a great risk, other scenarios leveraging the three bugs could let a threat actor hijack the connection between the mobile phone and an audio Bluetooth device and use the Bluetooth Hands-Free Profile (HFP) to issue commands to the phone.
</p>

<p>
	 
</p>

<p>
	“The range of available commands depends on the mobile operating system, but all major platforms support at least initiating and receiving calls” - <a href="https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/" rel="external nofollow" target="_blank">ERNW</a>
</p>

<p>
	 
</p>

<p>
	The researchers were able to trigger a call to an arbitrary number by extracting the Bluetooth link keys from a vulnerable device’s memory.
</p>

<p>
	 
</p>

<p>
	They say that depending on the phone’s configuration, an attacker could also retrieve the call history and contacts.
</p>

<p>
	 
</p>

<p>
	They were also able to initiate a call and "successfully eavesdrop on conversations or sounds within earshot of the phone."
</p>

<p>
	 
</p>

<p>
	Furthermore, the vulnerable device’s firmware could potentially be rewritten to enable remote code execution, thereby facilitating the deployment of a wormable exploit capable of propagating across multiple devices.
</p>

<h3>
	Attack restrictions apply
</h3>

<p>
	Although the ERNW researchers present serious attack scenarios, practical implementation at scale is constrained by certain limitations.
</p>

<p>
	 
</p>

<p>
	“Yes — the idea that someone could hijack your headphones, impersonate them towards your phone, and potentially make calls or spy on you, sounds pretty alarming.”
</p>

<p>
	 
</p>

<p>
	“Yes — technically, it is serious,” the researchers say, adding that “real attacks are complex to perform.”
</p>

<p>
	 
</p>

<p>
	The necessity of both technical sophistication and physical proximity confines these attacks to high-value targets, such as those in diplomacy, journalism, activism, or sensitive industries.
</p>

<p>
	 
</p>

<p>
	Airoha has released an updated SDK incorporating necessary mitigations, and device manufacturers have started patch development and distribution.
</p>

<p>
	 
</p>

<p>
	Nevertheless, German publication <a href="https://www.heise.de/en/news/Zero-day-Bluetooth-gap-turns-millions-of-headphones-into-listening-stations-10460704.html" rel="external nofollow" target="_blank">Heise says</a> that the most recent firmware updates for more than half of the affected devices are from May 27 or earlier, which is before Airoha delivered the updated SDK to its customers.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/bluetooth-flaws-could-let-hackers-spy-through-your-microphone/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29967</guid><pubDate>Sun, 29 Jun 2025 20:36:19 +0000</pubDate></item><item><title>Let&#x2019;s Encrypt ends certificate expiry emails to cut costs, boost privacy</title><link>https://nsaneforums.com/news/security-privacy-news/let%E2%80%99s-encrypt-ends-certificate-expiry-emails-to-cut-costs-boost-privacy-r29966/</link><description><![CDATA[<p>
	Let's Encrypt has announced it will no longer notify users about imminent certificate expirations via email due to high costs, privacy concerns, and unnecessary complexities.
</p>

<p>
	 
</p>

<p>
	The decision to end the expiration notification email service was implemented as of June 4, 2025, but Let's Encrypt has now communicated it via a blog post to raise awareness and prevent unexpected disruptions.
</p>

<p>
	 
</p>

<p>
	Let's Encrypt is a nonprofit Certificate Authority (CA) that provides free, automated, and open digital certificates to enable HTTPS (SSL/TLS) on websites. In terms of size, they are among the largest CAs in the world, issuing hundreds of millions of certificates to billions of websites.
</p>

<p>
	 
</p>

<p>
	Let's Encrypt is a transparent CA that has minimized data retention wherever possible. Its root certificate is included in all major browsers and OS trust stores, while it enjoys support from prominent tech firms such as Google, Cisco, Mozilla, EFF, Facebook, and Akamai.
</p>

<p>
	 
</p>

<p>
	The organization utilizes an automated protocol called ACME (Automatic Certificate Management Environment), which enables websites and server software to automate the issuance, installation, and renewal of certificates with minimal or no human intervention.
</p>

<p>
	 
</p>

<p>
	According to the <a href="https://letsencrypt.org/2025/06/26/expiration-notification-service-has-ended/" rel="external nofollow" target="_blank">latest announcement</a>, the existence of this automation is the primary reason why the email notification service is being sunset, as its need is diminishing.
</p>

<p>
	 
</p>

<p>
	The adoption of automated renewal solutions has been further accelerated by standards changes, such as the CA/Browser Forum's recent announcement to reduce certificate lifespans to 47 days by 2029.
</p>

<p>
	 
</p>

<p>
	This decision made manual management impractical, if not impossible, strongly incentivizing the adoption of automation to stay compliant and avoid outages.
</p>

<p>
	 
</p>

<p>
	A second key reason for the decision to drop the email service is the cost of running it, which Let's Encrypt estimates to be "tens of thousands of dollars per year."
</p>

<p>
	 
</p>

<p>
	The organization believes it would be far more beneficial to allocate this money to other aspects of its infrastructure, which is also unnecessarily strained by handling email distribution activities.
</p>

<p>
	 
</p>

<p>
	"Providing expiration notifications adds complexity to our infrastructure, which takes time and attention to manage and increases the likelihood of mistakes being made," explained Let's Encrypt.
</p>

<p>
	 
</p>

<p>
	"Over the long term, particularly as we add support for new service components, we need to manage overall complexity by phasing out system components that can no longer be justified."
</p>

<p>
	 
</p>

<p>
	Finally, the organization has user data privacy concerns, as it now has to retain, manage, and protect a sizable database of email addresses linked to issuance records to notify the appropriate parties.
</p>

<p>
	 
</p>

<p>
	The key takeaway for potentially impacted users is to adopt tools that support the ACME protocol if they haven't already done so and to stop relying on Let's Encrypt's notification emails.
</p>

<p>
	 
</p>

<p>
	If you need to receive renewal alerts, consider setting up an external notification service in a different manner.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/lets-encrypt-ends-certificate-expiry-emails-to-cut-costs-boost-privacy/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29966</guid><pubDate>Sun, 29 Jun 2025 20:35:14 +0000</pubDate></item><item><title>How vulnerable is critical infrastructure to cyberattack in the US?</title><link>https://nsaneforums.com/news/security-privacy-news/how-vulnerable-is-critical-infrastructure-to-cyberattack-in-the-us-r29949/</link><description><![CDATA[<h3>
	“We were always prey,” but there are surprisingly simple solutions to safeguard hospitals, water facilities, and other critical infrastructure.
</h3>

<p>
	Our water, health, and energy systems are increasingly vulnerable to cyberattack.
</p>

<p>
	 
</p>

<p>
	Now, when tensions escalate — like when the <a href="https://www.vox.com/politics/417505/iran-war-trump-nuclear-strategy-foreign-policy" rel="external nofollow">US bombed nuclear facilities in Iran</a> this month — the safety of these systems becomes of paramount concern. If conflict erupts, we can expect it to be a “hybrid” battle, <a href="https://securityandtechnology.org/team/undisruptable27-team/joshua-corman/" rel="external nofollow">Joshua Corman</a>, executive in residence for public safety &amp; resilience at the Institute for Security and Technology (IST), tells <em>The Verge</em>.
</p>

<p>
	 
</p>

<p>
	Battlefields now extend into the digital world, which in turn makes critical infrastructure in the real world a target. I first reached out to IST for their expertise on this issue back in 2021, when a ransomware attack forced the <a href="/2021/5/10/22429433/colonial-pipeline-cyber-security-ransomware-attack" rel="">Colonial Pipeline</a> — a major artery transporting nearly half of the east coast’s fuel supply — offline for nearly a week. Since then, <em>The Verge</em> has also covered an <a href="/2024/5/21/24161502/cyberattack-drinking-water-epa-inspection-enforcement-alert" rel="">uptick in cyberattacks against community water systems</a> in the US, and America’s <a href="/2024/8/9/24216329/cybersecurity-clean-energy-biden-administration-priorities" rel="">attempts to thwart</a> <a href="/2024/6/24/24185013/homeland-security-china-artificial-intelligence-priorities-memo-mayorkas" rel="">assaults</a> supported by other governments.
</p>

<p>
	 
</p>

<p>
	It’s not time to panic, Corman reassures me. But it is important to reevaluate how we safeguard hospitals, water supplies, and other lifelines from cyberattack. There happen to be analog solutions that rely more on physical engineering than putting up cyber firewalls.
</p>

<p>
	 
</p>

<p>
	<em>This interview has been edited for length and clarity.</em>
</p>

<p>
	 
</p>

<p>
	<strong>As someone who works on cybersecurity for water and wastewater, healthcare, food supply chains, and power systems — what keeps you up at night?</strong>
</p>

<p>
	 
</p>

<p>
	Oh, boy. When you look across what we designate as lifeline critical functions, the basic human needs — water, shelter, safety — those are among some of our most exposed and underprepared. With great connectivity comes great responsibility. And while we’re struggling to protect credit card cards or websites or data, we continue to add software and connectivity to lifeline infrastructure like water and power and hospitals.
</p>

<p>
	 
</p>

<p>
	We were always prey. We were just kind of surviving at the appetite of our predators, and they’re getting more aggressive.
</p>

<p>
	 
</p>

<p>
	<strong>How vulnerable are these systems in the US? </strong>
</p>

<p>
	 
</p>

<p>
	You might have seen the uptick in ransomware starting in 2016. Hospitals very quickly became the number one preferred target of ransomware because they’re what I call “target rich, but cyber poor.” The unavailability of their service is pretty dire, so the unavailability can be monetized very easily.
</p>

<p>
	 
</p>

<p>
	You have this kind of asymmetry and unmitigated feeding-frenzy, where it’s attractive and easy to attack these lifeline functions. But it’s incredibly difficult to get staff, resources, training, budget, to defend these lifeline functions.
</p>

<p>
	 
</p>

<p>
	If you’re a small, rural water facility, you don’t have any cybersecurity budget. We often usher platitudes of ‘just do best practices, just do the <a href="https://www.nist.gov/cyberframework" rel="external nofollow">NIST framework</a>.’ But they can’t even stop using end of life, unsupported technology with hard-coded passwords.
</p>

<p>
	 
</p>

<p>
	It’s about 85 percent of the owners and operators of these lifeline critical infrastructure entities that are target rich and cyber poor.
</p>

<p>
	 
</p>

<p>
	Take water systems, for example. <a href="/2024/5/21/24161502/cyberattack-drinking-water-epa-inspection-enforcement-alert" rel="">Volt Typhoon</a> has been found successfully compromising US water facilities and other lifeline service functions, and it’s sitting there in wait, prepositioning. [<em>Editor’s note: Volt Typhoon is </em><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a" rel="external nofollow"><em>a People’s Republic of China state-sponsored cyber group</em></a>]
</p>

<p>
	 
</p>

<p>
	China specifically has <a href="https://www.bloomberg.com/news/articles/2025-03-19/taiwan-sets-2027-for-possible-china-invasion-in-first-for-drills" rel="external nofollow">intentions toward Taiwan as early as 2027</a>. They basically would like the US to stay out of their intentions toward Taiwan. And if we don’t, they’re willing to disrupt and destroy parts of these very exposed, very prone facilities. The overwhelming majority don’t have a single cybersecurity person, haven’t heard of Volt Typhoon, let alone know if and how they should defend themselves. Nor do they have the budget to do so.
</p>

<p>
	 
</p>

<p>
	<strong>Turning to recent news and the escalation with Iran, is there anything that is more vulnerable at this moment? Are there any unique risks that Iran poses to the US? </strong>
</p>

<p>
	 
</p>

<p>
	Whether it’s Russia or Iran or China, all of them have shown they are willing and able to reach out to water facilities, power grids, hospitals, etc. I am most concerned about water. No water means no hospital in about four hours. Any loss of pressure to the hospital’s pressure zone means no fire suppression, no surgical scrubbing, no sanitation, no hydration.
</p>

<p>
	 
</p>

<p>
	What we have is increasing exposure that we volunteered into with smart, connected infrastructure. We want the benefit, but we haven’t paid the price tag yet. And that was okay when this was mostly criminal activity. But now that these points of access can be used in weapons of war, you could see pretty severe disruption in civilian infrastructure.
</p>

<p>
	 
</p>

<p>
	Now, just because you can hit it doesn’t mean you will hit it, right? I’m not encouraging panic at the moment over Iran. I think they’re quite busy, and if they’re going to use those cyber capabilities, it’s a safer assumption they would first use them on Israel.
</p>

<p>
	 
</p>

<p>
	Different predators have different appetites, and prey, and motives.
</p>

<p>
	 
</p>

<p>
	Sometimes it’s called access brokering, where they’re looking for a compromise and they lay in wait for years. Like in critical infrastructure, people don’t upgrade their equipment, they use very old things. If you believe that you’ll have that access for a long time, you can sit on it and wait patiently until the time and the place of your choosing.
</p>

<p>
	 
</p>

<p>
	Think of this a little bit like <em>Star Wars</em>. The thermal exhaust port on the Death Star is the weak part. If you hit it, you do a lot of damage. We have a lot of thermal exhaust ports all over water and healthcare specifically.
</p>

<p>
	 
</p>

<p>
	<strong>What needs to be done now to mitigate these vulnerabilities?</strong>
</p>

<p>
	 
</p>

<p>
	We’re encouraging something called <a href="https://inl.gov/national-security/cie/" rel="external nofollow">cyber-informed engineering</a>.
</p>

<p>
	 
</p>

<p>
	What we’ve found is if a water facility is compromised, abrupt changes in water pressure can lead to a very forceful and damaging surge of water pressure that could burst pipes. If you were to burst the water main for a hospital, there would be no water pressure to the hospital. So if you wanted to say, ‘let’s make sure the Chinese military can’t compromise the water facility,’ you’d have to do quite a bit of cybersecurity or disconnect it.
</p>

<p>
	 
</p>

<p>
	What we’re encouraging instead, is something much more familiar, practical. Just like in your house, you have a circuit breaker, so if there’s too much voltage you flip a switch instead of burning the house down. We have the equivalent of circuit breakers for water, which are maybe $2,000, maybe under $10,000. They can detect a surge in pressure and shut off the pumps to prevent physical damage. We’re looking for analog, physical engineering mitigation.
</p>

<p>
	 
</p>

<p>
	If you want to reduce the likelihood of compromise, you add cybersecurity. But if you want to reduce the <em>consequences</em> of compromise, you add engineering.
</p>

<p>
	 
</p>

<p>
	If the worst consequences would be a physically damaging attack, we want to take practical steps that are affordable and familiar. Water plants don’t know cyber, but they do know engineering. And if we can meet them on their turf and help explain to them the consequences and then co-create affordable, realistic, temporary mitigations, we can survive long enough to invest properly in cybersecurity later.
</p>

<p>
	 
</p>

<p>
	<strong>Federal agencies under the Trump administration have <a href="/politics/656674/the-100-day-inferno" rel="">faced budget and staffing cuts</a>, does that lead to greater vulnerabilities as well? How does that affect the security of our critical infrastructure? </strong>
</p>

<p>
	 
</p>

<p>
	Independent of people’s individual politics, there was an <a href="https://www.whitehouse.gov/presidential-actions/2025/03/achieving-efficiency-through-state-and-local-preparedness/" rel="external nofollow">executive order</a> from the White House in March that shifts more of the balance of power and responsibility to states to protect themselves, for cybersecurity resilience. And it’s very unfortunate timing given the context we’re in and that it would take time to do this safely and effectively.
</p>

<p>
	 
</p>

<p>
	I think, without malice, there has been a confluence of other contributing factors making the situation worse. Some of the <a href="/news/675027/several-of-cisas-top-officials-are-gone" rel="">budget cuts in</a> <a href="/news/675027/several-of-cisas-top-officials-are-gone" rel="">CISA</a>, which is the national coordinator across these sectors, is not great. The <a href="https://www.cisa.gov/resources-tools/services/multi-state-information-sharing-and-analysis-center" rel="external nofollow">Multi-State Information Sharing and Analysis Center</a> is a key resource for helping the states serve themselves, and that too <a href="https://statescoop.com/ms-isac-loses-federal-support/" rel="external nofollow">lost its funding</a>. And as of yet, the Senate has not confirmed a <a href="/news/627768/trump-nominates-sean-plankey-to-lead-the-cisa" rel="">CISA director</a>.
</p>

<p>
	 
</p>

<p>
	We should be increasing our public private partnerships, our federal and state level partnerships and there seems to be bipartisan agreement on that. And yet, across the board, the <a href="/environment/632688/epa-science-research-department-budget-cut-trump" rel="">EPA</a>, <a href="/news/640988/trump-rfk-health-human-services-cdc-fda-reductions" rel="">Health and Human Services</a>, <a href="https://www.politico.com/news/2025/06/17/trumps-energy-cuts-means-agencies-failure-00406526" rel="external nofollow">Department of Energy</a> and <a href="/news/675027/several-of-cisas-top-officials-are-gone" rel="">CISA</a> have suffered significant reduction in budget and staff and leadership. There’s still time to correct that, but we are burning daylight on what I see as a very small amount of time to form the plan, to communicate the plan, and execute the plan.
</p>

<p>
	 
</p>

<p>
	Whether we want this or not, more responsibility for cyber resilience and defense and critical functions is falling to the states, to the counties, to the towns, to individuals. Now is the time to get educated and there is a constellation of nonprofit and civil society efforts — one of them is the good work we’re doing with this <a href="http://Undisruptable27.org" rel="external nofollow">Undisruptable27.org</a>, but we also participate in a larger group called <a href="https://securityandtechnology.org/blog/ist-joins-cyber-civil-defense-initiative/" rel="external nofollow">Cyber Civil Defense.</a> And we recently launched a group called the <a href="https://cltc.berkeley.edu/program/cyber-resilience-corps/" rel="external nofollow">Cyber Resilience Corps</a>, which is a platform for anyone who wants to volunteer to help with cybersecurity for small, medium, rural, or lifeline services. It’s also a place for people to find and request these volunteers. We’re trying to reduce the friction of asking for help and finding help.
</p>

<p>
	 
</p>

<p>
	I think this is one of those moments in history where we want and need more from governments, but cavalry isn’t coming. It’s going to fall to us.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/cyber-security/693588/cybersecurity-cyberattack-critical-infrastructure-war-expert-iran" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29949</guid><pubDate>Sat, 28 Jun 2025 02:35:19 +0000</pubDate></item><item><title>Microsoft changes Windows in attempt to prevent next CrowdStrike-style catastrophe</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-changes-windows-in-attempt-to-prevent-next-crowdstrike-style-catastrophe-r29941/</link><description><![CDATA[<h3>
	AV vendors have worried that this could advantage Microsoft's security software.
</h3>

<p>
	In the summer of 2024, corporate anti-malware provider CrowdStrike <a href="https://arstechnica.com/information-technology/2024/07/major-outages-at-crowdstrike-microsoft-leave-the-world-with-bsods-and-confusion/" rel="external nofollow">pushed a broken update to millions of PCs and servers</a> running some version of Microsoft's Windows software, taking down systems that both companies and consumers relied on for air travel, payments, emergency services, and their morning coffee. It was a huge outage, and it caused days and weeks of pain as the world's permanently beleaguered IT workers brought systems back online, in some cases touching each affected PC individually to remove the bad update and get the systems back up and running.
</p>

<p>
	 
</p>

<p>
	The outage was ultimately CrowdStrike's fault, and in the aftermath of the incident, the company promised a long list of process improvements to keep a bad update like that from going out again. But because the outage affected Windows systems, Microsoft often had <a href="https://www.washingtonpost.com/business/2024/07/19/windows-outage-crowdstrike-cancellations-computer/" rel="external nofollow">shared</a> and sometimes even <a href="https://www.nytimes.com/2024/07/19/technology/microsoft-crowdstrike-outage-what-happened.html" rel="external nofollow">top billing</a> in mainstream news coverage—another in <a href="https://arstechnica.com/information-technology/2024/04/microsoft-blamed-for-a-cascade-of-security-failures-in-exchange-breach-report/" rel="external nofollow">a string of security-related embarrassments</a> that prompted <a href="https://arstechnica.com/information-technology/2024/05/microsoft-ties-executive-pay-to-security-following-multiple-failures-and-breaches/" rel="external nofollow">CEO Satya Nadella</a> and <a href="https://arstechnica.com/tech-policy/2024/06/microsoft-in-damage-control-mode-says-it-will-prioritize-security-over-ai/" rel="external nofollow">other executives</a> to promise that the company would refocus its efforts on improving the security of its products.
</p>

<p>
	 
</p>

<p>
	The CrowdStrike crash was possible partly due to how anti-malware software works in Windows. Security vendors and their AV products generally have access to the Windows kernel, the cornerstone of the operating system that sits between your hardware and most user applications. But most user applications don't have kernel access specifically because a buggy app (or one hijacked by malware) with kernel access can bring the entire system down rather than just affecting the app. The bad CrowdStrike update was bad mostly because it was being loaded so early in Windows' boot process that many systems couldn't check for and download CrowdStrike's fix before they crashed.
</p>

<p>
	 
</p>

<p>
	As part of <a href="https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/" rel="external nofollow">a wide-ranging security blog post</a> earlier this week, Microsoft announced a seemingly minor change that could have a big impact: "a private preview of the Windows endpoint security platform" that "will allow [endpoint security vendors] to start building their solutions to run outside the Windows kernel."
</p>

<p>
	 
</p>

<p>
	"This means security products like anti-virus and endpoint protection solutions can run in user mode just as apps do," wrote David Weston, Microsoft's VP of Enterprise and OS Security. "This change will help security developers provide a high level of reliability and easier recovery resulting in less impact on Windows devices in the event of unexpected issues."
</p>

<p>
	 
</p>

<p>
	This preview will be delivered to companies that participate in Microsoft's Microsoft Virus Initiative (MVI), a list that includes CrowdStrike, Bitdefender, ESET, SentinelOne, Trellix, Trend Micro, and WithSecure. Those companies all have representatives quoted in Microsoft's blog post, all offering some version of (to paraphrase) "security is important and we are pleased to be working with Microsoft to make it better."
</p>

<p>
	 
</p>

<p>
	Microsoft's language says that security vendors <em>can</em> develop security apps that operate in user mode but not that they <em>must</em> do so. It's not clear whether this announcement is a first step toward booting third-party security companies out of the Windows kernel entirely or if it's simply a new, more foolproof option for companies whose software doesn't need that level of access.
</p>

<h2>
	An idea with some baggage
</h2>

<p>
	Microsoft's attempts to restrict third-party security companies from accessing the Windows kernel have been contentious in the past. Back in 2006, when Microsoft was simultaneously developing Windows Vista and building the foundation for what would become today's 64-bit editions of Windows, Microsoft <a href="https://arstechnica.com/information-technology/2006/10/7998/" rel="external nofollow">wanted to restrict security companies</a> from patching the kernel as they'd been able to in 32-bit editions of Windows, insisting that they do so using more restricted security APIs instead.
</p>

<p>
	 
</p>

<p>
	But Microsoft was also <a href="https://arstechnica.com/uncategorized/2006/05/6952-2/" rel="external nofollow">beginning to offer its own antivirus products at the time</a>, including the first version of Windows Defender. Companies like Symantec argued that restricting their access to the kernel was anti-competitive and that it would give Microsoft's own security products capabilities that third parties couldn't provide.
</p>

<p>
	 
</p>

<p>
	Working with third-party companies to define these standards and address those companies' concerns seems to be Microsoft's way of trying to avoid that kind of controversy this time around.
</p>

<p>
	 
</p>

<p>
	"We will continue to collaborate deeply with our MVI partners throughout the private preview," wrote Weston.
</p>

<h2>
	Death comes for the blue screen
</h2>

<figure class="ars-wp-img-shortcode id-2103359 align-fullwidth">
	<div>
		<img alt="black-screen-of-death.png" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/black-screen-of-death.png">
	</div>

	<figcaption>
		<div class="caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300">
			<div class="caption-content">
				<em>Microsoft is changing the "b" in BSoD, but that's less interesting than the under-the-hood changes. <span class="caption-credit mt-2 text-xs"><em> </em></span></em>
			</div>

			<div class="caption-content">
				<em><span class="caption-credit mt-2 text-xs"><em>Credit: Microsoft </em></span> </em>
			</div>
		</div>
	</figcaption>
</figure>

<p>
	Microsoft's post outlines a handful of other security-related Windows tweaks, including some that take alternate routes to preventing more CrowdStrike-esque outages.
</p>

<p>
	 
</p>

<p>
	Multiple changes are coming for the "unexpected restart screen," the less-derogatory official name for what many Windows users know colloquially as the "blue screen of death." For starters, the screen will now be black instead of blue, a change that Microsoft briefly attempted to make in the early days of Windows 11 <a href="https://arstechnica.com/gadgets/2021/11/next-windows-11-update-makes-the-blue-screen-of-death-blue-again/" rel="external nofollow">but subsequently rolled back</a>.
</p>

<p>
	 
</p>

<p>
	The unexpected restart screen has been "simplified" in a way that "improves readability and aligns better with Windows 11 design principles, while preserving the technical information on the screen for when it is needed."
</p>

<p>
	 
</p>

<p>
	But the more meaningful change is under the hood, in the form of a new feature called "quick machine recovery" (QMR).
</p>

<p>
	 
</p>

<p>
	If a Windows PC has multiple unexpected restarts or gets into a boot loop—as happened to many systems affected by the CrowdStrike bug—the PC will try to boot into Windows RE, a stripped-down recovery environment that offers a handful of diagnostic options and can be used to enter Safe Mode or open the PC's UEFI firmware. QMR will allow Microsoft to "broadly deploy targeted remediations to affected devices via Windows RE," making it possible for some problems to be fixed even if the PCs can't be booted into standard Windows, "quickly getting users to a productive state without requiring complex manual intervention from IT."
</p>

<p>
	 
</p>

<p>
	QMR will be enabled by default on Windows 11 Home, while the Pro and Enterprise versions will be configurable by IT administrators. The QMR functionality and the black version of the blue screen of death will both be added to Windows 11 24H2 later this summer. Microsoft plans to add additional customization options for QMR "later this year."
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2025/06/microsoft-is-trying-to-get-antivirus-software-away-from-the-windows-kernel/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29941</guid><pubDate>Fri, 27 Jun 2025 21:32:18 +0000</pubDate></item><item><title>Android phones could soon warn you of &#x201C;Stingrays&#x201D; snooping on your communications</title><link>https://nsaneforums.com/news/security-privacy-news/android-phones-could-soon-warn-you-of-%E2%80%9Cstingrays%E2%80%9D-snooping-on-your-communications-r29936/</link><description><![CDATA[<h3>
	But it requires specific hardware support that is missing on current phones.
</h3>

<p>
	Smartphones contain a treasure trove of personal data, which makes them a worthwhile target for hackers. However, law enforcement is not above snooping on cell phones, and their tactics are usually much harder to detect. <a href="https://arstechnica.com/tech-policy/2013/09/meet-the-machines-that-steal-your-phones-data/" rel="external nofollow">Cell site simulators</a>, often called Stingrays, can trick your phone into revealing private communications, but a change in Android 16 could allow phones to detect this spying.
</p>

<p>
	 
</p>

<p>
	Law enforcement organizations have massively <a href="https://arstechnica.com/tech-policy/2018/07/judge-slams-fbi-for-improper-cellphone-search-stingray-use/" rel="external nofollow">expanded the use of Stingray devices</a> because almost every person of interest today uses a cell phone at some point. These devices essentially trick phones into connecting to them like a normal cell tower, allowing the operator to track that device's location. The fake towers can also shift a phone to less secure wireless technology to intercept calls and messages. There's no indication this is happening on the suspect's end, which is another reason these machines have become so popular with police.
</p>

<p>
	 
</p>

<p>
	However, while surveilling a target, Stingrays can collect data from other nearby phones. It's not unreasonable to expect a modicum of privacy if you happen to be in the same general area, but sometimes police use Stingrays simply <a href="https://arstechnica.com/tech-policy/2015/05/county-sheriff-has-used-stingray-over-300-times-with-no-warrant/" rel="external nofollow">because they can</a>. There's also evidence that cell simulators have been deployed by <a href="https://arstechnica.com/tech-policy/2018/04/dhs-to-senator-malicious-use-of-stingrays-is-a-real-and-growing-risk/" rel="external nofollow">mysterious groups outside law enforcement</a>. In short, it's a <em>problem</em>. Google has had plans to address this security issue for more than a year, but a lack of hardware support has slowed progress. Finally, in the coming months, we will see the first phones capable of detecting this malicious activity, and Android 16 is ready for it.
</p>

<figure class="ars-wp-img-shortcode id-2103418 align-fullwidth">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="Network notifications on Android" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/Notification-for-connection-to-unencrypted-cellular-network.jpg-1024x511.webp">
				<div class="pswp-caption-content" id="caption-2103418">
					<em>An example of the network notifications that could appear on future Android phones. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Credit: Android Authority </em></em>
					</div>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	As part of Google's mobile network security features, Android phones will be able to detect when a network requests a unique identifier or attempts to force an unencrypted connection. This produces a "network notification" to warn of the potential attack. This settings page will also include a toggle to disable insecure 2G networks, which is already supported in Android.
</p>

<p>
	 
</p>

<p>
	The problem, however, is that no current phones can do this. To unmask fake cell towers, Android phones need to have version 3.0 of Google's IRadio hardware abstraction layer, which has to be supported at the modem level. Even Google's <a href="https://arstechnica.com/gadgets/2025/04/google-pixel-9a-review-all-the-phone-you-need/" rel="external nofollow">latest Pixel phones</a> lack support, so the network security settings page is hidden in current builds of Android 16.
</p>

<figure class="ars-wp-img-shortcode id-616685 align-fullwidth">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="stingray.png" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2015/02/stingray.png">
				<div class="pswp-caption-content" id="caption-616685">
					<em>The Stingray, made by Harris Corp., is now so ubiquitous in law enforcement that it has become a generic term for cell site simulators. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Credit: US Patent and Trademark Office </em></em>
					</div>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	According to <a href="https://www.androidauthority.com/android-16-mobile-network-security-3571497/" rel="external nofollow">Android Authority</a>, Google allows OEMs to lock in certain hardware features at the time of a phone's release. So it's unlikely any current phone will be updated with modem drivers that are capable of Stingray detection. Phones that launch on Android 16 later this year, like the Pixel 10, will be the first to call out fake cell towers. In the meantime, you can still disable 2G connections to limit the impact of cell site simulators.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2025/06/future-android-phones-could-warn-you-about-data-stealing-fake-cell-towers/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29936</guid><pubDate>Fri, 27 Jun 2025 21:19:34 +0000</pubDate></item><item><title>Retail giant Ahold Delhaize says data breach affects 2.2 million people</title><link>https://nsaneforums.com/news/security-privacy-news/retail-giant-ahold-delhaize-says-data-breach-affects-22-million-people-r29935/</link><description><![CDATA[<p>
	Ahold Delhaize, one of the world's largest food retail chains, is notifying over 2.2 million individuals that their personal, financial, and health information was stolen in a November ransomware attack that impacted its U.S. systems.
</p>

<p>
	 
</p>

<p>
	The multinational retailer and wholesale company operates over 9,400 local stores across Europe, the United States, and Indonesia, employing more than 393,000 people and serving approximately 60 million customers each week in-store and online.
</p>

<p>
	 
</p>

<p>
	It has reported yearly net sales of over $104 billion last year and it operates under a wide range of brands, including Food Lion, Stop &amp; Shop, Giant Food, and Hannaford in the American market, and Delhaize, Maxi, Mega Image, Albert, bol, Alfa Beta, Gall &amp; Gall, and Profi in Europe.
</p>

<p>
	 
</p>

<p>
	"This issue and subsequent mitigating actions have affected certain Ahold Delhaize USA brands and services including a number of pharmacies and certain e-commerce operations," <a href="https://newsroom.aholddelhaize.com/ahold-delhaize-statement-on-ahold-delhaize-usa-cybersecurity-issue/" rel="external nofollow" target="_blank">said Ahold Delhaize</a> in November, when it disclosed the incident.
</p>

<p>
	 
</p>

<p>
	In a Thursday <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/b17963fc-3806-430e-b28e-bac47eb73a8b.html" rel="external nofollow" target="_blank">filing</a> with Maine's Attorney General, the retail giant revealed that the attackers behind the November breach stole the data of 2,242,521 individuals after gaining access to the company's internal U.S. business systems on November 6, 2024.
</p>

<p>
	 
</p>

<p>
	While it didn't confirm whether customers' information was also affected, Ahold Delhaize stated that the stolen files may have included internal employment records with personal information obtained while working with current and former Ahold Delhaize USA companies.
</p>

<p>
	 
</p>

<p>
	The company added that the stolen items vary for each affected individual and that the stolen documents contain a combination of:
</p>

<p>
	 
</p>

<ul style="list-style-type:square">
	<li>
		personal information such as name, contact information (e.g., postal and email address and telephone number), date of birth, government-issued identification numbers (e.g., Social Security, passport, and driver's license numbers),
	</li>
	<li>
		financial account information (e.g., bank account number),
	</li>
	<li>
		health information (e.g., workers' compensation information and medical information contained in employment records),
	</li>
	<li>
		and employment-related information.
	</li>
</ul>

<p>
	 
</p>

<p>
	Although the company has yet to name the cybercrime group behind the breach, the INC Ransom ransomware group added Ahold Delhaize to its dark web extortion portal in April, leaking samples of documents allegedly stolen from the company's compromised systems.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Ahold Delhaize entry on INC Ransom's leak site" class="ipsImage" height="394" width="720" src="https://www.bleepstatic.com/images/news/security/d/data-breaches/a/ahold/inc-ahold.jpg">
		<figcaption>
			<em>Ahold Delhaize on INC Ransom's leak site (BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<p>
	Ahold Delhaize <a href="https://www.bleepingcomputer.com/news/security/ahold-delhaize-confirms-data-theft-after-inc-ransomware-claims-attack/" rel="external nofollow" target="_blank">told BleepingComputer</a> in April that attackers had stolen data from its U.S. business systems but didn't comment on whether the ransomware gang was involved in the breach.
</p>

<p>
	 
</p>

<p>
	Today, an Ahold Delhaize spokesperson once again refused to comment when asked to confirm that INC Ransom was behind the attack, if any systems were encrypted during the attack, and whether the company had been in contact with the attackers about paying a ransom.
</p>

<p>
	 
</p>

<p>
	"It’s important to note that based on our investigation, we have no indication that customer payment or pharmacy systems were compromised in connection with the issue, and the company identified no customer credit card numbers contained in the affected files. Beyond this, we are not providing any additional details on the systems affected," BleepingComputer was told.
</p>

<p>
	 
</p>

<p>
	INC Ransom is a ransomware-as-a-service (RaaS) operation that surfaced in July 2023 and has since targeted organizations in both the public and private sectors.
</p>

<p>
	 
</p>

<p>
	Its list of more than 250 victims claimed over the last two years includes government, healthcare, educational, and industrial entities, such as Scotland's <a href="https://www.bleepingcomputer.com/news/security/inc-ransom-threatens-to-leak-3tb-of-nhs-scotland-stolen-data/" rel="external nofollow" target="_blank">National Health Service</a> (NHS), <a href="https://www.bleepingcomputer.com/news/security/yamaha-motor-confirms-ransomware-attack-on-philippines-subsidiary/" rel="external nofollow" target="_blank">Yamaha Motor Philippines</a>, and the U.S. division of <a href="https://www.bleepingcomputer.com/news/security/xerox-says-subsidiary-xbs-us-breached-after-ransomware-gang-leaks-data/" rel="external nofollow" target="_blank">Xerox Business Solutions</a> (XBS).
</p>

<p>
	 
</p>

<p>
	In April, the ransomware gang also claimed responsibility for an attack on the <a href="https://www.bleepingcomputer.com/news/security/texas-state-bar-warns-of-data-breach-after-inc-ransomware-claims-attack/" rel="external nofollow" target="_blank">State Bar of Texas,</a> which later warned over 100,000 members that hackers had stolen their sensitive data.
</p>

<p>
	 
</p>

<p>
	INC Ransom has recently shifted its focus to organizations in the United States, with one of its members, tracked by Microsoft as '<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-vanilla-tempest-hackers-hit-healthcare-with-inc-ransomware/" rel="external nofollow" target="_blank">Vanilla Tempest</a>,' specifically targeting U.S. healthcare providers.
</p>

<p>
	 
</p>

<p>
	<em>Update June 27, 13:32 EDT: Added Ahold Delhaize statement.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/retail-giant-ahold-delhaize-says-data-breach-affects-22-million-people/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29935</guid><pubDate>Fri, 27 Jun 2025 21:18:33 +0000</pubDate></item><item><title>Google&#x2019;s AI video tool amplifies fears of an increase in misinformation</title><link>https://nsaneforums.com/news/security-privacy-news/google%E2%80%99s-ai-video-tool-amplifies-fears-of-an-increase-in-misinformation-r29929/</link><description><![CDATA[<div id="slice-container-newsletterForm-articleInbodyContent-wcGfqBup6q9KPf5twdeUhD">
	<div data-hydrate="true">
		<h3>
			<em>Experts say Veo 3 makes it very easy to make fake videos that can spread false news.</em>
		</h3>

		<p>
			In both <a href="https://www.aljazeera.com/news/2025/6/21/tehran-is-in-shock-and-we-have-fled-with-heavy-hearts" rel="external nofollow" target="_blank">Tehran</a> and <a href="https://www.aljazeera.com/gallery/2025/6/24/the-aftermath-of-iranian-missile-strikes-in-israel" rel="external nofollow" target="_blank">Tel Aviv</a>, residents have faced heightened anxiety in recent days as the threat of missile strikes looms over their communities. Alongside the very real concerns for physical safety, there is growing alarm over the role of misinformation, particularly content generated by artificial intelligence, in shaping public perception.
		</p>

		<p>
			 
		</p>

		<p>
			GeoConfirmed, an online verification platform, has <a href="https://x.com/GeoConfirmed/status/1934331634775433372" rel="external nofollow" target="_blank">reported an increase in AI-generated misinformation</a>, including fabricated videos of air strikes that never occurred, both in Iran and Israel.
		</p>

		<p>
			 
		</p>

		<p>
			This follows a similar wave of manipulated footage that circulated during recent protests in Los Angeles, which were sparked by a <a href="https://www.aljazeera.com/news/2025/6/7/ice-launches-military-style-raids-in-los-angeles-what-we-know" rel="external nofollow" target="_blank">rise in immigration raids</a> in the second-most populous city in the United States.
		</p>

		<p>
			 
		</p>

		<p>
			The developments are part of a broader trend of politically charged events being exploited to spread false or misleading narratives.
		</p>

		<p>
			 
		</p>

		<p>
			The launch of a new AI product by one of the largest tech companies in the world has added to those concerns of detecting fact from fiction.
		</p>

		<p>
			 
		</p>

		<p>
			Late last month, Google’s AI research division, DeepMind, released Veo 3, a tool capable of generating eight-second videos from text prompts. The system, one of the most comprehensive ones currently available for free, produces highly realistic visuals and sound that can be difficult for the average viewer to distinguish from real footage.
		</p>

		<p>
			 
		</p>

		<p>
			To see exactly what it can do, Al Jazeera created a fake video in minutes using a prompt depicting a protester in New York claiming to be paid to attend, a common talking point Republicans historically have used to delegitimise protests, accompanied by footage that appeared to show violent unrest. The final product was nearly indistinguishable from authentic footage.
		</p>

		<p>
			 
		</p>

		<p>
			Al Jazeera also created videos showing fake missile strikes in both Tehran and Tel Aviv using the prompts “show me a bombing in Tel Aviv” and then a similar prompt for Tehran. Veo 3 says on its website that it blocks “harmful requests and results”, but Al Jazeera had no problems making these fake videos.
		</p>

		<p>
			 
		</p>

		<p>
			“I recently created a completely synthetic video of myself speaking at Web Summit using nothing but a single photograph and a few dollars. It fooled my own team, trusted colleagues, and security experts,” said Ben Colman, CEO of deepfake detection firm Reality Defender, in an interview with Al Jazeera.
		</p>

		<p>
			 
		</p>

		<p>
			“If I can do this in minutes, imagine what motivated bad actors are already doing with unlimited time and resources.”
		</p>

		<p>
			 
		</p>

		<p>
			He added, “We’re not preparing for a future threat. We’re already behind in a race that started the moment Veo 3 launched. Robust solutions do exist and work — just not the ones the model makers are offering as the be-all, end-all.”
		</p>

		<p>
			Google says it is taking the issue seriously.
		</p>

		<p>
			 
		</p>

		<p>
			“We’re committed to developing AI responsibly, and we have clear policies to protect users from harm and govern the use of our AI tools. Any content generated with Google AI includes a SynthID watermark, and we add a visible watermark to Veo videos as well,” a company spokesperson told Al Jazeera.
		</p>

		<h2 id="they-don-t-care-about-customers">
			‘They don’t care about customers’
		</h2>

		<p>
			However, experts say the tool was released before those features were fully implemented, a move some believe was reckless.
		</p>

		<p>
			 
		</p>

		<p>
			Joshua McKenty, CEO of deepfake detection company Polyguard, said that Google rushed the product to market because it had been lagging behind competitors like OpenAI and Microsoft, which have released more user-friendly and publicised tools. Google did not respond to these claims.
		</p>

		<p>
			 
		</p>

		<div class="ipsEmbeddedVideo" contenteditable="false">
			<div>
				<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/LMVa-DsegiQ?feature=oembed" title="Is AI reshaping the creative landscape? | The Stream" width="200"></iframe>
			</div>
		</div>

		<p>
			 
		</p>

		<p>
			 
		</p>

		<p>
			“Google’s trying to win an argument that their AI matters when they’ve been losing dramatically,” McKenty said. “They’re like the third horse in a two-horse race. They don’t care about customers. They care about their own shiny tech.”
		</p>

		<p>
			 
		</p>

		<p>
			That sentiment was echoed by Sukrit Venkatagiri, an assistant professor of computer science at Swarthmore College.
		</p>

		<p>
			 
		</p>

		<p>
			“Companies are in a weird bind. If you don’t develop generative AI, you’re seen as falling behind and your stock takes a hit,” he said. “But they also have a responsibility to make these products safe when deployed in the real world. I don’t think anyone cares about that right now. All of these companies are putting profit — or the promise of profit — over safety.”
		</p>

		<p>
			 
		</p>

		<div class="ipsEmbeddedVideo" contenteditable="false">
			<div>
				<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/N1x8LxgeKEQ?feature=oembed" title="Can AI be held accountable? AI ethicist on tech giants and the AI boom | UpFront" width="200"></iframe>
			</div>
		</div>

		<p>
			 
		</p>

		<p>
			Google’s own research, published last year, acknowledged the threat generative AI poses.
		</p>

		<p>
			 
		</p>

		<p>
			“The explosion of generative AI-based methods has inflamed these concerns [about misinformation], as they can synthesise highly realistic audio and visual content as well as natural, fluent text at a scale previously impossible without an enormous amount of manual labour,” <a href="https://arxiv.org/html/2405.11697v2#:~:text=The%20explosion%20of%20generative%20AI,number%20of%20harms%20%5B9%5D%20." rel="external nofollow" target="_blank">the study read</a>.
		</p>

		<p>
			Demis Hassabis, CEO of Google DeepMind, has long warned his colleagues in the AI industry against prioritising speed over safety. “I would advocate not moving fast and breaking things,” he told Time in 2023.
		</p>

		<p>
			 
		</p>

		<p>
			He declined Al Jazeera’s request for an interview.
		</p>

		<p>
			 
		</p>

		<p>
			Yet despite such warnings, Google released Veo 3 before fully implementing safeguards, leading to incidents like the one the National Guard had to debunk in Los Angeles after a TikTok account made a fake “day in the life” video of a soldier that said he was preparing for “today’s gassing” — referring to releasing tear gas on protesters.
		</p>

		<h2 id="mimicking-real-events">
			Mimicking real events
		</h2>

		<p>
			The implications of Veo 3 extend far beyond protest footage. In the days following its release, several fabricated videos mimicking real news broadcasts circulated on social media, including one of a false report about a home break-in that included CNN graphics.
		</p>

		<p>
			 
		</p>

		<p>
			Another clip falsely claimed that JK Rowling’s yacht sank off the coast of Turkiye after an orca attack, attributing the report to Alejandra Caraballo of Harvard Law’s Cyberlaw Clinic, who built the video to test out the tool.
		</p>

		<p>
			 
		</p>

		<p>
			<a href="https://bsky.app/profile/esqueer.net/post/3lpnkgkk24c2f" rel="external nofollow" target="_blank">In a post,</a> Caraballo warned that such tech could mislead older news consumers in particular.
		</p>

		<p>
			 
		</p>

		<p>
			“What’s worrying is how easy it is to repeat. Within ten minutes, I had multiple versions. This makes it harder to detect and easier to spread,” she wrote. “The lack of a chyron [banner on a news broadcast] makes it trivial to add one after the fact to make it look like any particular news channel.”
		</p>

		<p>
			 
		</p>

		<p>
			In our own experiment, we used a prompt to create fake news videos bearing the logos of ABC and NBC, with voices mimicking those of CNN anchors Jake Tapper, Erin Burnett, John Berman, and Anderson Cooper.
		</p>

		<p>
			 
		</p>

		<p>
			“Now, it’s just getting harder and harder to tell fact from fiction,” Caraballo told Al Jazeera. “As someone who’s been researching AI systems for years, even I’m starting to struggle.”
		</p>

		<p>
			 
		</p>

		<p>
			This challenge extends to the public, as well. A study by <a href="https://www.psu.edu/news/research/story/video-fake-news-believed-more-shared-more-text-and-audio-versions" rel="external nofollow">Penn State University found that 48</a> percent of consumers were fooled by fake videos circulated via messaging apps or social media.
		</p>

		<p>
			 
		</p>

		<p>
			Contrary to popular belief,<a href="https://today.yougov.com/politics/articles/45855-americans-distinguish-real-fake-news-headline-poll" rel="external nofollow" target="_blank"> younger adults are more susceptible</a> to misinformation than older adults, largely because younger generations rely on social media for news, which lacks the editorial standards and legal oversight of traditional news organisations.
		</p>

		<p>
			 
		</p>

		<p>
			A <a href="https://www.unesco.org/en/articles/2/3-digital-content-creators-do-not-check-their-facts-sharing-want-learn-how-do-so-unesco-survey" rel="external nofollow" target="_blank">UNESCO survey from December</a> showed that 62 percent of news influencers do not fact-check information before sharing it.
		</p>

		<p>
			 
		</p>

		<p>
			Google is not alone in developing tools that facilitate the spread of synthetic media. Companies like Deepbrain offer users the ability to create AI-generated avatar videos, though with limitations, as it cannot produce full-scene renders like Veo 3. Deepbrain did not respond to Al Jazeera’s request for comment. Other tools like Synthesia and Dubverse allow video dubbing, primarily for translation.
		</p>

		<p>
			 
		</p>

		<p>
			This growing toolkit offers more opportunities for malicious actors. A recent incident involved a fabricated news segment in which a CBS reporter in Dallas was made to appear to say racist remarks. The software used remains unidentified.
		</p>

		<p>
			 
		</p>

		<p>
			CBS News Texas did not respond to a request for comment.
		</p>

		<p>
			 
		</p>

		<p>
			As synthetic media becomes more prevalent, it poses unique risks that will allow bad actors to push manipulated content that spreads faster than it can be corrected, according to Colman.
		</p>

		<p>
			 
		</p>

		<p>
			“By the time fake content spreads across platforms that don’t check these markers [which is most of them], through channels that strip them out, or via bad actors who’ve learned to falsify them, the damage is done,” Colman said.
		</p>

		<p>
			 
		</p>

		<p>
			<a href="https://www.aljazeera.com/economy/2025/6/26/googles-ai-video-tool-amplifies-fears-of-an-increase-in-misinformation" rel="external nofollow">Source</a>
		</p>

		<hr class="ipsHr">
		<p>
			<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
		</p>

		<p>
			<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">29929</guid><pubDate>Fri, 27 Jun 2025 04:41:00 +0000</pubDate></item><item><title>Actively exploited vulnerability gives extraordinary control over server fleets</title><link>https://nsaneforums.com/news/security-privacy-news/actively-exploited-vulnerability-gives-extraordinary-control-over-server-fleets-r29928/</link><description><![CDATA[<h3>
	AMI MegaRAC used in servers from AMD, ARM, Fujitsu, Gigabyte, Supermicro, and Qualcomm.
</h3>

<p>
	Hackers are exploiting a maximum-severity vulnerability that has the potential to give them complete control over thousands of servers, many of which handle mission-critical tasks inside data centers, the US Cybersecurity and Infrastructure Security Agency is warning.
</p>

<p>
	 
</p>

<p>
	The vulnerability, carrying a severity rating of 10 out of a possible 10, resides in the AMI MegaRAC, a widely used firmware package that allows large fleets of servers to be remotely accessed and managed even when power is unavailable or the operating system isn't functioning. These motherboard-attached microcontrollers, known as baseboard management controllers (BMCs), give extraordinary control over servers inside data centers.
</p>

<p>
	 
</p>

<p>
	Administrators use BMCs to reinstall operating systems, install or modify apps and make configuration changes to large numbers of servers, without physically being on premises and, in many cases, without the servers being turned on. Successful compromise of a single BMC can be used to pivot into internal networks and compromise all other BMCs.
</p>

<h2>
	We don’t need no stinkin’ credentials
</h2>

<p>
	CVE-2024-54085, as the vulnerability is tracked, allows for authentication bypasses by making a simple web request to a vulnerable BMC device over HTTP. The vulnerability was discovered by security firm Eclypsium and <a href="https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/" rel="external nofollow">disclosed</a> in March. The disclosure included proof-of-concept exploit code allowing a remote attacker to create an admin account without providing any authentication. At the time of the disclosure, there were no known reports of the vulnerability being actively exploited.
</p>

<p>
	 
</p>

<p>
	On Wednesday, CISA <a href="https://www.cisa.gov/news-events/alerts/2025/06/25/cisa-adds-three-known-exploited-vulnerabilities-catalog" rel="external nofollow">added</a> CVE-2024-54085 to its list of vulnerabilities known to be exploited in the wild. The notice provided no further details.
</p>

<p>
	 
</p>

<p>
	In an email on Thursday, Eclypsium researchers said the scope of the exploits has the potential to be broad. That scope includes:
</p>

<blockquote class="QuoteNewsStyle">
	<ul>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">Attackers could chain multiple BMC exploits to implant malicious code directly into the BMC’s firmware, making their presence extremely difficult to detect and allowing them to survive OS reinstalls or even disk replacements.</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">By operating below the OS, attackers can evade endpoint protection, logging, and most traditional security tools.</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">With BMC access, attackers can remotely power on or off, reboot, or reimage the server, regardless of the primary operating system's state.</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">Attackers can scrape credentials stored on the system, including those used for remote management, and use the BMC as a launchpad to move laterally within the network</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">BMCs often have access to system memory and network interfaces, enabling attackers to sniff sensitive data or exfiltrate information without detection</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">Attackers with BMC access can intentionally corrupt firmware, rendering servers unbootable and causing significant operational disruption</span>
		</li>
	</ul>
</blockquote>

<p>
	With no publicly known details of the ongoing attacks, it's unclear which groups may be behind them. Eclypsium said the most likely culprits would be espionage groups working on behalf of the Chinese government. All five of the specific APT groups Eclypsium named have a history of exploiting firmware vulnerabilities or gaining persistent access to high-value targets.
</p>

<p>
	 
</p>

<p>
	Eclypsium said the line of vulnerable AMI MegaRAC devices uses an interface known as Redfish. Server makers known to use these products include AMD, Ampere Computing, ASRock, ARM, Fujitsu, Gigabyte, Huawei, Nvidia, Supermicro, and Qualcomm. Some, but not all, of these vendors have released patches for their wares.
</p>

<p>
	 
</p>

<p>
	Given the damage possible from exploitation of this vulnerability, admins should examine all BMCs in their fleets to ensure they aren't vulnerable. With products from so many different server makers affected, admins should consult with their manufacturer when unsure if their networks are exposed.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/06/active-exploitation-of-ami-management-tool-imperils-thousands-of-servers/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29928</guid><pubDate>Fri, 27 Jun 2025 04:25:53 +0000</pubDate></item><item><title>Brother printer bug in 689 models exposes default admin passwords</title><link>https://nsaneforums.com/news/security-privacy-news/brother-printer-bug-in-689-models-exposes-default-admin-passwords-r29914/</link><description><![CDATA[<p>
	A total of 689 printer models from Brother, along with 53 other models from Fujifilm, Toshiba, and Konica Minolta, come with a default administrator password that remote attackers can generate. Even worse, there is no way to fix the flaw via firmware in existing printers.
</p>

<p>
	 
</p>

<p>
	The flaw, tracked under <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51978" rel="external nofollow" target="_blank">CVE-2024-51978</a>, is part of a set of eight vulnerabilities <a href="https://www.rapid7.com/blog/post/multiple-brother-devices-multiple-vulnerabilities-fixed/" rel="external nofollow" target="_blank">discovered by Rapid7 researchers</a> during a lengthy examination of Brother hardware.
</p>

<p>
	 
</p>

<table border="1px solid black;">
	<thead>
		<tr>
			<th>
				CVE
			</th>
			<th>
				Description
			</th>
			<th>
				Affected Service
			</th>
			<th>
				CVSS
			</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td>
				CVE-2024-51977
			</td>
			<td>
				An unauthenticated attacker can leak sensitive information.
			</td>
			<td>
				HTTP (Port 80), HTTPS (Port 443), IPP (Port 631)
			</td>
			<td>
				5.3 (Medium)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51978
			</td>
			<td>
				An unauthenticated attacker can generate the device's default administrator password.
			</td>
			<td>
				HTTP (Port 80), HTTPS (Port 443), IPP (Port 631)
			</td>
			<td>
				9.8 (Critical)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51979
			</td>
			<td>
				An authenticated attacker can trigger a stack based buffer overflow.
			</td>
			<td>
				HTTP (Port 80), HTTPS (Port 443), IPP (Port 631)
			</td>
			<td>
				7.2 (High)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51980
			</td>
			<td>
				An unauthenticated attacker can force the device to open a TCP connection.
			</td>
			<td>
				Web Services over HTTP (Port 80)
			</td>
			<td>
				5.3 (Medium)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51981
			</td>
			<td>
				An unauthenticated attacker can force the device to perform an arbitrary HTTP request.
			</td>
			<td>
				Web Services over HTTP (Port 80)
			</td>
			<td>
				5.3 (Medium)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51982
			</td>
			<td>
				An unauthenticated attacker can crash the device.
			</td>
			<td>
				PJL (Port 9100)
			</td>
			<td>
				7.5 (High)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51983
			</td>
			<td>
				An unauthenticated attacker can crash the device.
			</td>
			<td>
				Web Services over HTTP (Port 80)
			</td>
			<td>
				7.5 (High)
			</td>
		</tr>
		<tr>
			<td>
				CVE-2024-51984
			</td>
			<td>
				An authenticated attacker can disclose the password of a configured external service.
			</td>
			<td>
				LDAP, FTP
			</td>
			<td>
				6.8 (Medium)
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	This crucial vulnerability can be chained with other vulnerabilities discovered by Rapid7 to determine the admin password, take control of devices, perform remote code execution, crash them, or pivot within the networks they're connected to.
</p>

<p>
	 
</p>

<p>
	Not all of the flaws affect every one of the 689 Brother printer models, but other manufacturers, including Fujifilm (46 models), Konica Minolta (6), Ricoh (5), and Toshiba (2), are impacted as well.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Number of impacted models for each of the eight flaws" class="ipsImage" height="304" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/June/impact.jpg">
		<figcaption>
			<em>Number of impacted models for each of the eight flaws<br>
			Source: Rapid7</em>
		</figcaption>
	</figure>
</div>

<h2>
	Insecure password generation
</h2>

<p>
	The default password in the impacted printers is generated during manufacturing using a custom alogirthm based on the device's serial number.
</p>

<p>
	 
</p>

<p>
	According to a <a href="https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf" rel="external nofollow" target="_blank">detailed technical analysis</a> by Rapid7, the password generation algorithm follows an easily reversible process:
</p>

<p>
	 
</p>

<ol>
	<li>
		Take the first 16 characters of the serial number.
	</li>
	<li>
		Append 8 bytes derived from a static "salt" table.
	</li>
	<li>
		Hash the result with SHA256.
	</li>
	<li>
		Base64-encode the hash.
	</li>
	<li>
		Take the first eight characters and substitute some letters with special characters.
	</li>
</ol>

<p>
	 
</p>

<p>
	Attackers can leak the serial number of the target printer using various methods or by exploiting <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51977" rel="external nofollow" target="_blank">CVE-2024-51977</a>. They can then use the algorithm to generate the default admin password and log in as admin.
</p>

<p>
	 
</p>

<p>
	From there, they may reconfigure the printer, access stored scans, read address books, exploit <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51979" rel="external nofollow" target="_blank">CVE-2024-51979</a> for remote code execution, or exploit <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51984" rel="external nofollow" target="_blank">CVE-2024-51984</a> to harvest credentials.
</p>

<p>
	 
</p>

<p>
	Rapid7 began its disclosure process in May 2024 and was aided by JPCERT/CC in coordinating disclosures to other manufacturers.
</p>

<p>
	 
</p>

<p>
	Although all flaws have been fixed in firmware updates made available by impacted manufacturers, the case with CVE-2024-51978 is complicated in terms of risk management.
</p>

<p>
	 
</p>

<p>
	The vulnerability is rooted in the password generation logic used in hardware manufacturing, and hence, any devices made before its discovery will have predictable passwords unless users change them.
</p>

<p>
	 
</p>

<p>
	"Brother has indicated that this vulnerability cannot be fully remediated in firmware, and has required a change to the manufacturing process of all affected models," explains Rapid7 regarding CVE-2024-51978.
</p>

<p>
	 
</p>

<p>
	Users of existing Brother printers listed in the impacted models should consider their devices vulnerable and immediately change the default admin password, followed by applying the firmware updates.
</p>

<p>
	 
</p>

<p>
	In general, it is recommended to restrict access to the printer's admin interfaces over unsecured protocols and external networks.
</p>

<p>
	 
</p>

<p>
	Security bulletins with instructions on what users should do are available for <a href="https://support.brother.com/g/b/faqend.aspx?c=us&amp;lang=en&amp;prod=group2&amp;faqid=faq00100846_000" rel="external nofollow" target="_blank">Brother</a>, <a href="https://www.konicaminolta.com/global-en/security/advisory/pdf/km-2025-0001.pdf" rel="external nofollow" target="_blank">Konica Minolta</a>, <a href="https://www.fujifilm.com/fbglobal/eng/company/news/notice/2025/0625_announce.html" rel="external nofollow" target="_blank">Fujifilm</a>, <a href="https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000007" rel="external nofollow" target="_blank">Ricoh</a>, and <a href="https://www.toshibatec.com/information/20250625_02.html" rel="external nofollow" target="_blank">Toshiba</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/brother-printer-bug-in-689-models-exposes-default-admin-passwords/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29914</guid><pubDate>Thu, 26 Jun 2025 21:16:24 +0000</pubDate></item></channel></rss>
