<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/4/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Exchange Server has a "critical" security bug, but Microsoft does not have a proper fix yet</title><link>https://nsaneforums.com/news/security-privacy-news/exchange-server-has-a-critical-security-bug-but-microsoft-does-not-have-a-proper-fix-yet-r35006/</link><description><![CDATA[<h3>
	A newly disclosed Exchange Server vulnerability is forcing some admins into messy trade-offs, and not everyone will receive Microsoft's permanent fix.
</h3>

<p>
	Although Exchange Online is Microsoft's recommended configuration to <a href="https://www.neowin.net/news/microsoft-will-begin-blocking-legacy-tls-connections-in-exchange-online-soon/" rel="external nofollow">keep your platform modern and updated</a>, Exchange Server continues to be the backbone for many enterprise clients' infrastructure. Now, the Redmond tech firm has issued an advisory that may trouble Exchange Server customers.
</p>

<p>
	 
</p>

<p>
	Basically, there is a security vulnerability in Exchange Server 2016, 2019, and SE, which enables an attacker to execute arbitrary JavaScript code in the victim's browser context by sending them a specially crafted email that has to be opened in Outlook Web Access (OWA) and interacted with in a certain way. It's being <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" rel="external nofollow">tracked as CVE-2026-42897 here</a> and has been assigned a max severity ranking of "critical".
</p>

<p>
	 
</p>

<p>
	For now, Microsoft is <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" rel="external nofollow">offering</a> two mitigations. The first one is the recommended approach and requires customers to enable the Exchange EM Service, which automatically mitigates this attack vector. It is important to note that this service was released in September 2021 and is enabled by default, so only customers who explicity disabled it are impacted.
</p>

<p>
	 
</p>

<p>
	The second mitigation is for customers who have disabled the Exchange EM Service for any reason. They are advised to apply the scripted mitigation process described <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" rel="external nofollow">here</a>.
</p>

<p>
	 
</p>

<p>
	However, neither of these two methods are robust fixes, as they will lead to other issues, detailed below:
</p>

<p>
	 
</p>

<ul>
	<li>
		OWA Print Calendar functionality might not work. As a workaround copy the data or screenshot the calendar you want to print or use Outlook Desktop client.
	</li>
	<li>
		Inline images might not display correctly in the recipients OWA reading pane. As a workaround, send images as email attachments or use Outlook Desktop client.
	</li>
	<li>
		OWA light (OWA URL ending in /?layout=light) does not work properly. Please note that this feature has been deprecated several years ago and is not intended for regular production use.
	</li>
	<li>
		We are aware of the mitigation showing the "Mitigation invalid for this exchange version." in mitigation details. This issue is cosmetic and the mitigation DOES apply successfully if the status is shown as "Applied". We are investigating on how to address this.
	</li>
</ul>

<p>
	 
</p>

<p>
	The good news is that Microsoft is working on a proper and robust fix. Exchange SE will receive it as a public update while Exchange 2016 and 2019 updates will only be offered to customers who have <a href="https://www.neowin.net/news/microsoft-kicks-off-phase-2-of-paid-esu-program-for-some-legacy-software/" rel="external nofollow">paid for Period 2 of the Exchange Server Extended Security Updates (ESU) program</a>. Period 1 customers will not get the update as their program expired in April 2026. Finally, Exchange Online users can rest easy as they are not impacted by this security vulnerability at all.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/exchange-server-has-a-critical-security-bug-but-microsoft-does-not-have-a-proper-fix-yet/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 15 May 2026 at 6:10 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35006</guid><pubDate>Fri, 15 May 2026 08:11:01 +0000</pubDate></item><item><title>Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026</title><link>https://nsaneforums.com/news/security-privacy-news/windows-11-and-microsoft-edge-hacked-at-pwn2own-berlin-2026-r35001/</link><description><![CDATA[<p>
	On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days.
</p>

<p>
	 
</p>

<p>
	Today's highlight was Orange Tsai's attempt, who was awarded $175,000 in rewards after <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlslrhjrvc2s" rel="external nofollow" target="_blank">chaining 4 logic bugs</a> to achieve a sandbox escape on Microsoft Edge.
</p>

<p>
	 
</p>

<p>
	Windows 11 was also hacked three times by <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlsterlyhk2d" rel="external nofollow" target="_blank">Angelboy and TwinkleStar03</a> (working with the DEVCORE Internship Program), <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlsyezpkyc2m" rel="external nofollow" target="_blank">Marcin Wiązowski</a>, and <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mltgpmo7ac2p" rel="external nofollow" target="_blank">Kentaro Kawane</a> of GMO Cybersecurity, each earning $30,000 in cash rewards for demonstrating new privilege escalation zero-days.
</p>

<p>
	 
</p>

<p>
	Valentina Palmiotti (chompie) of IBM X-Force Offensive Research (XOR) also collected $20,000 after <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mltebpvjlc2p" rel="external nofollow" target="_blank">rooting Red Hat Linux for Workstations</a> and another $50,000 for a <a href="http://bsky.app/profile/thezdi.bsky.social/post/3mlsm3vbvks2s" rel="external nofollow" target="_blank">zero-day in the NVIDIA Container Toolkit</a>.
</p>

<p>
	 
</p>

<p>
	Other successful attempts include k3vg3n chaining 3 bugs to <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlso3j67ns2s" rel="external nofollow" target="_blank">take down LiteLLM</a> ($40,000), <a href="http://bsky.app/profile/thezdi.bsky.social/post/3mlsottlmak2s" rel="external nofollow" target="_blank">Satoki Tsuji</a> and <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mltcik6cvs2w" rel="external nofollow" target="_blank">haehae</a> exploiting NVIDIA Megatron Bridge zero-days ($20,000), <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlst4byglc2d" rel="external nofollow" target="_blank">Compass Security</a> and <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlswuldquc2m" rel="external nofollow" target="_blank">maitai of Doyensec</a> hacking OpenAI's Codex coding agent (each earning $40,000), haehae <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlt5kuba622z" rel="external nofollow" target="_blank">dropping a Chroma zero-day</a> ($20,000), and STARLabs SG <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mltheam2ps2p" rel="external nofollow" target="_blank">a LM Studio zero-day</a> ($40,000). 
</p>

<p>
	 
</p>

<p>
	The DEVCORE Research Team is now <a href="https://bsky.app/profile/thezdi.bsky.social/post/3mlti4xn3d22p" rel="external nofollow" target="_blank">leading the competition</a> with $205,000, followed by Valentina Palmiotti with $70,000.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/8ngMzEVrdVs?feature=oembed" title="Pwn2Own Berlin 2026 Day 1 - DEVCORE vs Microsoft Edge" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div id="tpYtContainer">
	<p>
		The <a href="https://www.zerodayinitiative.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026" rel="external nofollow" target="_blank">Pwn2Own Berlin 2026</a> hacking contest, which focuses on enterprise technologies and artificial intelligence, takes place <span style="box-sizing:border-box; margin:0px; padding:0px">at the <a href="https://www.offensivecon.org/" rel="external nofollow" target="_blank">OffensiveCon</a> conference from May 14 to</span> May 16.
	</p>

	<p>
		 
	</p>

	<p>
		<a href="https://www.zerodayinitiative.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day2" rel="external nofollow" target="_blank">On the second day</a>, the competitors will also attempt to exploit zero-days in Microsoft SharePoint, Microsoft Exchange, Windows 11, Apple Safari, Cursor, Red Hat Enterprise Linux for Workstations, LM Studio, OpenAI Codex, LiteLLM, Anthropic Claude Code, and Mozilla Firefox.
	</p>

	<p>
		 
	</p>
</div>

<p>
	Security researchers targeting fully patched products in the web browser, virtualization, local privilege escalation, servers, enterprise applications, cloud-native/container, local inference, and LLM categories can earn over $1,000,000 in cash and prizes.
</p>

<p>
	 
</p>

<p>
	<span style="box-sizing:border-box; margin:0px; padding:0px">According to <a href="https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html" rel="external nofollow" target="_blank">Pwn2Own's rules</a>, all targeted devices run the latest operating system versions, and all entries must compromise the target and demonstrate arbitrary code execution.</span>
</p>

<p>
	 
</p>

<p>
	After the zero-day flaws are disclosed during the Pwn2Own competition, vendors have 90 days to release security fixes for their software and hardware products.
</p>

<p>
	 
</p>

<p>
	Last year, TrendMicro's Zero Day Initiative <a href="https://www.bleepingcomputer.com/news/security/hackers-earn-1-078-750-for-28-zero-days-at-pwn2own-berlin/" rel="external nofollow" target="_blank">awarded 1,078,750</a> for 29 zero-day vulnerabilities and some bug collisions.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 15 May 2026 at 7:31 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">35001</guid><pubDate>Thu, 14 May 2026 21:32:59 +0000</pubDate></item><item><title>Nightmare-Eclipse drops YellowKey and GreenPlasma exploits for Windows 11</title><link>https://nsaneforums.com/news/security-privacy-news/nightmare-eclipse-drops-yellowkey-and-greenplasma-exploits-for-windows-11-r34990/</link><description><![CDATA[<h3>
	New vulnerabilities released on Patch Tuesday target BitLocker encryption and system privileges on Windows 11 and Server 2025.
</h3>

<p>
	GitHub user Nightmare-Eclipse has just published two new vulnerabilities called YellowKey and GreenPlasma that affect Windows 11 systems. They were both released on May 12, the same day that Microsoft published its <a href="https://www.neowin.net/news/windows-11-kb5089549-patch-tuesday-brings-xbox-mode-file-explorer-improvements-and-more/" rel="external nofollow">Patch Tuesday updates</a>, creating a big headache for the Redmond giant.
</p>

<p>
	 
</p>

<p>
	The first of the two exploits, <a href="https://github.com/Nightmare-Eclipse/YellowKey" rel="external nofollow">YellowKey</a>, is a bypass vulnerability affecting BitLocker only on Windows 11. According to the Nightmare-Eclipse, YellowKey feels like a backdoor put in by Microsoft that could allow law enforcement to get past the encryption, but this is an unproven allegation at this point.
</p>

<p>
	 
</p>

<p>
	YellowKey relies on an actor copying the published FsTx folder to a USB stick, plugging the stick into a target Windows computer that has BitLocker switched on, and then rebooting into the Windows Recovery Environment Agent while holding down a series of keys. If you do everything properly, it brings up a shell that has unrestricted access to the BitLocker-protected volume.
</p>

<p>
	 
</p>

<p>
	Explaining why they think that this is a backdoor, Nightmare-Eclipse says:
</p>

<p>
	 
</p>

<p style="margin-left:40px">
	“Now why would I say this is a backdoor ? The component that is responsible for this bug is not present anywhere (even in the internet) except inside WinRE image and what makes it raise suspicions is the fact that the exact same component is also present with the exact same name in a normal windows installation but without the functionalities that trigger the bitlocker bypass issue. Why ? I just can't come up with an explanation besides the fact that this was intentional.”
</p>

<p>
	 
</p>

<p>
	It’s noted that this vulnerability only affects Windows 11, Windows Server 2022, and Windows Server 2025, but Windows 10 is not affected.
</p>

<div class="img-center">
	<figure class="image image--expandable">
		<img alt="The GreenPlasma exploit" class="ipsImage" height="406" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/05/1778737033_591244383-3a843a4b-8daf-4fc9-9d95-26f87b67031b.webp">
		<figcaption>
			<em>Credit: Nightmare-Eclipse // GreenPlasma exploit</em>
		</figcaption>
	</figure>
</div>

<p>
	The second of the exploits is called <a href="https://github.com/Nightmare-Eclipse/GreenPlasma" rel="external nofollow">GreenPlasma</a>, which can give an attacker elevated privileges, allowing them to damage systems or steal data. Luckily, the proof of concept code published will not give an attacker full SYSTEM shell access. Unluckily, a “smart” person can turn this into a full privilege escalation that could pose a risk to the public.
</p>

<p>
	 
</p>

<p>
	The proof of concept creates an arbitrary memory section object in any directory object write-able by SYSTEM, leveraging the Collaborative Translation Framework (CTF) which is known to be insecure and has been at the center of <a href="https://projectzero.google/2019/08/down-rabbit-hole.html" rel="external nofollow">previous vulnerabilities</a>.
</p>

<p>
	 
</p>

<p>
	It’s unclear how Microsoft will react to this news, hopefully it can get things quickly patched up and push a fix sooner than next month’s Patch Tuesday so that users don’t get harmed. You can bet that malicious actors will use these exploits, especially GreenPlasma, to do harm to the public.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/nightmare-eclipse-drops-yellowkey-and-greenplasma-exploits-for-windows-11/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 14 May 2026 at 4:26 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34990</guid><pubDate>Thu, 14 May 2026 06:27:53 +0000</pubDate></item><item><title>Cyber-crime increasingly coming with threats of physical violence</title><link>https://nsaneforums.com/news/security-privacy-news/cyber-crime-increasingly-coming-with-threats-of-physical-violence-r34947/</link><description><![CDATA[<p>
	A few years ago, Tim Beasley opened his front door to discover that a small package had been left on the step.
</p>

<p>
	 
</p>

<p>
	"I was like 'what the heck is this?'. I opened the box, and went 'oh!', and I immediately threw it away."
</p>

<p>
	 
</p>

<p>
	Inside the box was a threatening note, alluding to physical violence if he didn't back off.
</p>

<p>
	 
</p>

<p>
	Beasley works for a US security firm called Semperis, and at the time he was involved in ransom negotiations on behalf of a US government organisation that had been hit by a cyber-attack.
</p>

<p>
	 
</p>

<p>
	The package delivered to his home in the US was a warning from the ransomware group he had been having to talk to.
</p>

<p>
	<br />
	Cyber-attacks continue to soar around the world. In the US alone, the number of reported instances has increased from 288,012 in 2015 to 1,008,597 last year, a record high, according to new figures from the FBI.
</p>

<p>
	 
</p>

<p>
	It said that the resulting financial loss for US companies and other organisations totalled $20.8bn (£15.4bn) in 2025. That was up from $16.6bn in 2024.
</p>

<p>
	Meanwhile, cyber-attacks in the UK also hit new highs last year.
</p>

<p>
	 
</p>

<p>
	Usually in such instances the hackers try to infiltrate a company's computer system to steal sensitive data, or to take control and lock out the business. The cyber criminals then demand money for the return of the data, or to hand the system back to the firm in question.
</p>

<p>
	 
</p>

<p>
	But an increasing number of cyber attackers are now going further in their efforts to extort their victims - and threatening actual violence. The number of such physical threats rose more than twofold last year in the US, FBI annual data shows.
</p>

<p>
	 
</p>

<p>
	Separate research from Semperis found that in as many as 40% of global ransomware attacks in 2025, the criminals threatened to physically harm members of staff who refused to pay a ransom demand.
</p>

<p>
	 
</p>

<p>
	The phenomenon was said to be even more widespread in the US, where companies experienced physical threats 46% of the time.
</p>

<p>
	 
</p>

<p>
	"It's always been here in the background, but it's becoming more of a reality, slowly inching its way up," says Beasley.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="ec859160-3ee7-11f1-a821-9161fbfb806d.jpg" class="ipsImage" data-ratio="75.10" height="405" width="720" src="https://ichef.bbci.co.uk/news/1024/cpsprodpb/9a15/live/ec859160-3ee7-11f1-a821-9161fbfb806d.jpg.webp" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">Tim Beasley had a threatening note left on his doorstep</span>
</p>

<p>
	 
</p>

<p>
	Hackers are threatening staff after accessing their personal data, including their home addresses. That was the case with one hospital ransom negotiation that Zac Warren from US security firm Tanium worked on.
</p>

<p>
	 
</p>

<p>
	"We started getting reports that employees within the hospital were getting phone calls," says the chief security advisor for Europe and the Middle East. "So they were calling into the hospital… and asking for nurses by their name, and then talking to them and telling them that they knew where they lived.
</p>

<p>
	 
</p>

<p>
	"They gave them street addresses, they gave them social security numbers, they did all of these things to make people really feel like they were being watched. They had all this information, so there's a really strong level of intimidation of the clinicians that was taking place."
</p>

<p>
	 
</p>

<p>
	Sometimes, the threat of physical harm is less direct - but no less potentially lethal. In some cases, for example, attackers have been able to take control of manufacturing machinery and demonstrate their control by turning devices such as robots and conveyor belts on and off - actions that could easily lead to injuries or even death.
</p>

<p>
	 
</p>

<p>
	Many ransomware gangs are state-sponsored, and threats of violence have been seen coming from Russia, China, Iran, and in some cases North Korea.
</p>

<p>
	 
</p>

<p>
	However, most physical threats tend to come from purely financially-motivated groups. These hackers are often very young. The FBI's profile of one such group indicated an age range of mostly between 17 and 25.
</p>

<p>
	 
</p>

<p>
	In many cases such cyber-criminals are said to pay others to threaten the violence, or actually carry it out.
</p>

<p>
	 
</p>

<p>
	"They themselves [the hackers], in a lot of cases don't want to get their own hands dirty," says Beasley. So instead they will post on message boards or social media to "do some recruiting, offer some cash and then people get hit or they get stalked".
</p>

<p>
	 
</p>

<p>
	Some of the most severe threats of violence - and actual physical attacks - are to be found in the murky world of cryptocurrency investment. Last May, for example, French police rescued the father of a cryptocurrency millionaire who had been kidnapped and held for ransom in a Paris suburb.
</p>

<p>
	 
</p>

<p>
	According to media reports the victim had one of his fingers cut off.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="d7a7efa0-3eeb-11f1-a821-9161fbfb806d.jpg" class="ipsImage" data-ratio="75.10" height="405" width="720" src="https://ichef.bbci.co.uk/news/1024/cpsprodpb/f249/live/d7a7efa0-3eeb-11f1-a821-9161fbfb806d.jpg.webp" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">Police in Paris had to rescue a man who had been kidnapped earlier this year</span>
</p>

<p>
	 
</p>

<p>
	Last year in Europe, including the UK, there were more than 18 such cases, according to one report. The study said there had been a "dramatic increase" in cybercrime involving physical attacks.
</p>

<p>
	 
</p>

<p>
	Europol, the law enforcement agency of the European Union, investigates such crime as part of its wider efforts to catch the perpetrators of all "violence as a service", where individuals carry out attacks for a fee.
</p>

<p>
	 
</p>

<p>
	In the US, the FBI issued an alert last summer, warning about the increased risk of violence from a network of online-linked criminals called "In Real Life Com".
</p>

<p>
	 
</p>

<p>
	These criminals, it said, are becoming increasingly aggressive, and happy to offer violence-as-a-service.
</p>

<p>
	 
</p>

<p>
	"If you are looking for something bad to happen to somebody you can find somebody that's willing to take that action for you within 'The Com'," says Adam Meyers, senior VP for counter adversary operations at cybersecurity software firm Crowdstrike.
</p>

<p>
	 
</p>

<p>
	"That could be throwing bricks through a window, it could be setting something on fire, it could be a shooting or it could be a kidnapping. Lower technically-sophisticated people will probably gravitate more towards violence-as-a-service because violence is often the only thing they have that they can bring to the party."
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="45d444f0-3ee8-11f1-a821-9161fbfb806d.jpg" class="ipsImage" data-ratio="75.10" height="404" width="720" src="https://ichef.bbci.co.uk/news/1024/cpsprodpb/7873/live/45d444f0-3ee8-11f1-a821-9161fbfb806d.jpg.webp" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">Zac Warren says that affected workers can face "really strong levels of intimidation"</span>
</p>

<p>
	 
</p>

<p>
	In the cryptocurrency cases, adds Meyers, the victims have probably drawn attention to themselves by being careless about what they reveal on social media, showing off about their success.
</p>

<p>
	 
</p>

<p>
	"Cryptocurrency people tend to have discussions about it in a way that you don't find with people who maybe have gold," he says. "They're online talking about trading cryptocurrency and how much money they've made, trying to get followers and get attention. As you do that, you're drawing attention to yourself."
</p>

<p>
	 
</p>

<p>
	Beasley says that threats of violence linked to cybercrime will likely only continue to rise "because people keep paying" as a result of it. "They don't want their kids getting kidnapped."
</p>

<p>
	 
</p>

<p>
	He adds: "It does make you want to look behind your back."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.bbc.com/news/articles/cr71d8vyjv0o" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">34947</guid><pubDate>Mon, 11 May 2026 10:06:14 +0000</pubDate></item><item><title>JDownloader site hacked to replace installers with Python RAT malware</title><link>https://nsaneforums.com/news/security-privacy-news/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware-r34928/</link><description><![CDATA[<p>
	The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying a Python-based remote access trojan.
</p>

<p>
	 
</p>

<p>
	The supply chain attack affects those who downloaded installers from the official website between May 6 and May 7, 2026 via the Windows "Download Alternative Installer" links or the Linux shell installer.
</p>

<p>
	 
</p>

<p>
	According to the developers, the attackers modified the website's download links to point to malicious third-party payloads rather than legitimate installers.
</p>

<p>
	 
</p>

<p>
	JDownloader is a widely used free download management application that supports automated downloads from file-hosting services, video sites, and premium link generators. The software has been available for more than a decade and is used by millions worldwide across Windows, Linux, and macOS.
</p>

<h2>
	The JDownloader supply chain attack
</h2>

<p>
	The compromise was first reported on <a href="https://old.reddit.com/r/jdownloader/comments/1t6goqe/is_the_website_hacked/" rel="external nofollow" target="_blank">Reddit</a> by a user named "PrinceOfNightSky," who noticed that downloaded installers were being flagged by Microsoft Defender.
</p>

<p>
	 
</p>

<p>
	"I been using Jdownloader and switched to a new PC a few weeks ago. Luckily I had the installer in a usb drive but decided to download the latest version," posted PrinceOfNightSky to Reddit.
</p>

<p>
	 
</p>

<p>
	"The website is official but all the Exes for windows are being reported as malicious software by windows and the developer is being listed as 'Zipline LLC.' And other times it's saying 'The Water Team' The software is obviously by Appwork and I have to manually unblock it from windows to run it which I will not do."
</p>

<p>
	 
</p>

<p>
	The JDownloader developers <a href="https://old.reddit.com/r/jdownloader/comments/1t6goqe/is_the_website_hacked/okhg2ur/" rel="external nofollow" target="_blank">later confirmed</a> that the site had been compromised and took the website offline to investigate the incident.
</p>

<p>
	 
</p>

<p>
	In an <a href="https://jdownloader.org/incident_8.5.2026.html?v=20260508277000" rel="external nofollow" target="_blank">incident report</a>, the devs said their website was compromised by attackers exploiting an unpatched vulnerability that allowed them to change website access control lists and content without authentication.
</p>

<p>
	 
</p>

<p>
	"Changes were made through the website's content management system, affecting published pages and links," reads the incident report.
</p>

<p>
	 
</p>

<p>
	"The attacker did not gain access to the underlying server stack — in particular no access to the host filesystem or broader operating-system-level control beyond CMS-managed web content."
</p>

<p>
	 
</p>

<p>
	The developers stated that the compromise affected only the alternative Windows installer download links and the Linux shell installer link. In-app updates, macOS downloads, Flatpak, Winget, Snap packages, and the main JDownloader JAR package were not modified.
</p>

<p>
	 
</p>

<p>
	The developers also said that users can confirm if an installer is legitimate by right-clicking the file, selecting <strong>Properties</strong>, and then clicking the <strong>Digital Signatures</strong> tab.
</p>

<p>
	 
</p>

<p>
	If Digital Signatures shows it was signed by "AppWork GmbH," then it is legitimate. However, if the file is not signed or is by a different name, it should be avoided.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Signed legitimate JDownloader installer" class="ipsImage" height="720" width="573" src="https://www.bleepstatic.com/images/news/security/attacks/j/jsdownloader-supply-chain-attack/jdownloader-signed.jpg">
		<figcaption>
			<em>Signed legitimate JDownloader installer<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	The JDownloader team said that analyzing the malicious payloads was "out of our scope," but shared an archive of the malicious installers so that others could analyze them.
</p>

<p>
	 
</p>

<p>
	Cybersecurity researcher <a href="https://x.com/thomasklemenc/status/2052715025450598904" rel="external nofollow" target="_blank">Thomas Klemenc</a> analyzed the malicious Windows executables and shared indicators of compromise (IOCs) for the malware.
</p>

<p>
	 
</p>

<p>
	According to Klemenc, the malware acts as a loader that deploys a heavily obfuscated Python-based RAT. 
</p>

<p>
	 
</p>

<p>
	Klemenc said the Python payload acts as a modular bot and RAT framework, allowing attackers to execute Python code delivered from the command and control (C2) servers.
</p>

<p>
	 
</p>

<p>
	The researcher also shared two command and control servers used by the malware:
</p>

<pre style="margin-left: 40px;"><code>https://parkspringshotel[.]com/m/Lu6aeloo.php
https://auraguest[.]lk/m/douV2quu.php</code></pre>

<p>
	BleepingComputer's analysis of the modified Linux shell installer found malicious code injected into the script that downloads an archive from 'checkinnhotels[.]com' disguised as an SVG file.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Malicious code in modified JDownloader Linux installer" class="ipsImage" height="322" width="720" src="https://www.bleepstatic.com/images/news/security/attacks/j/jsdownloader-supply-chain-attack/malicious-code-in-jdownloader-linux-installer.jpg">
		<figcaption>
			<em>Malicious code in the modified JDownloader Linux installer<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	Once downloaded, the script extracts two ELF binaries named 'pkg` and `systemd-exec` and then installs 'systemd-exec' as a SUID-root binary in '/usr/bin/'.
</p>

<p>
	 
</p>

<p>
	The installer then copied the main payload to '/root/.local/share/.pkg', created a persistence script in '/etc/profile.d/systemd.sh', and launched the malware while masquerading as '/usr/libexec/upowerd`.
</p>

<p>
	 
</p>

<p>
	The 'pkg' payload is also heavily obfuscated using Pyarmor, so it is unclear what functionality it performs.
</p>

<p>
	 
</p>

<p>
	JDownloader says users are only at risk if they downloaded and executed the affected installers while the site was compromised.
</p>

<p>
	 
</p>

<p>
	As arbitrary code could have been executed by the malware on infected devices, those who installed the malicious installers are advised to reinstall their operating systems.
</p>

<p>
	 
</p>

<p>
	It is also possible that credentials were compromised on devices, so it is strongly advised to reset passwords after cleaning the devices.
</p>

<p>
	 
</p>

<p>
	Hackers have increasingly targeted the websites of popular software tools this year to distribute malware to unsuspecting users.
</p>

<p>
	 
</p>

<p>
	In April, hackers <a href="https://www.bleepingcomputer.com/news/security/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor/" rel="external nofollow" target="_blank">compromised the CPUID website</a> to change download links that served malicious executables for the popular CPU-Z and HWMonitor tools.
</p>

<p>
	 
</p>

<p>
	Earlier this month, threat actors <a href="https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/" rel="external nofollow" target="_blank">compromised the DAEMONTOOLS website</a> to distribute trojanized installers containing a backdoor.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 10 May 2026 at 7:23 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34928</guid><pubDate>Sat, 09 May 2026 21:25:46 +0000</pubDate></item><item><title>Meta has killed end-to-end encryption on Instagram</title><link>https://nsaneforums.com/news/security-privacy-news/meta-has-killed-end-to-end-encryption-on-instagram-r34927/</link><description><![CDATA[<h3>
	As of today, end-to-end encryption is no longer available for DMs on Instagram, and Meta said you should consider WhatsApp if you need the feature.
</h3>

<p>
	Starting today, end-to-end encryption (E2EE) is no longer available for direct messages on Instagram, as Meta has removed the privacy feature years after it began testing it.
</p>

<p>
	 
</p>

<p>
	According to Meta, end-to-end encryption on Instagram was going away <a href="https://www.pcmag.com/news/meta-shuts-down-end-to-end-encryption-for-instagram-dms-messaging" rel="external nofollow">because</a> "very few people" were using it. This was not a surprise since the feature was a manual opt-in that was buried in chat settings on a per-conversation basis. The company's official line is that anyone who wanted hardcore encrypted chats could just switch to WhatsApp, and that anyone "<a href="https://help.instagram.com/491565145294150" rel="external nofollow">impacted by this change</a>" would see instructions on how to download any media or messages they want to keep before the system shuts them out.
</p>

<p>
	 
</p>

<p>
	E2EE basically means that only the sender and the recipient can decode and read a message, shielding it from hackers, law enforcement, and even the platform hosting the chat. Even though E2EE on Instagram is basically gone, all chats will still be encrypted with the standard transport-level encryption. This protects your data as it travels between your device and Meta's servers, but it means Meta holds the key and can absolutely read your DMs on its end.
</p>

<p>
	 
</p>

<p>
	E2EE has faced serious criticisms from child safety groups and law enforcement, who argued it created a digital black box for predators. A lawsuit filed by New Mexico's Attorney General revealed internal documents from 2019 that showed Meta's Head of Content Policy, Monika Bickert, warning her team that E2EE would prevent the company from finding child exploitation. She <a href="https://www.reuters.com/legal/government/meta-executive-warned-facebook-messenger-encryption-plan-was-so-irresponsible-2026-02-24/" rel="external nofollow">wrote</a> in a chat, "We are about to do a bad thing as a company. This is so irresponsible."
</p>

<p>
	 
</p>

<p>
	Two months ago, <a href="https://www.neowin.net/news/tiktok-says-it-is-protecting-you-by-letting-cops-read-your-private-messages/" rel="external nofollow">TikTok came out</a> to confirm it would never add E2EE to its direct messages, a decision that got a round of applause from child safety advocates. The company argued that keeping messages readable on its servers is a necessary safety feature because its user base is overwhelmingly young. Like Instagram, TikTok is using standard transport-level encryption to protect messages while they are in transit.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/meta-has-killed-end-to-end-encryption-on-instagram/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 10 May 2026 at 7:21 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34927</guid><pubDate>Sat, 09 May 2026 21:23:03 +0000</pubDate></item><item><title>The Canvas Hack Is a New Kind of Ransomware Debacle</title><link>https://nsaneforums.com/news/security-privacy-news/the-canvas-hack-is-a-new-kind-of-ransomware-debacle-r34926/</link><description><![CDATA[<p>
	<span style="font-size:16px;"><strong>Thousands of schools around the US were paralyzed on Thursday after education tech firm Instructure shut down access to its Canvas platform following a breach by hackers going by the name ShinyHunters.</strong></span>
</p>

<p>
	 
</p>

<p>
	<strong>Higher education has</strong> long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.
</p>

<p>
	 
</p>

<p>
	The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker "ShinyHunters." Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.
</p>

<p>
	 
</p>

<p>
	Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark-web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.
</p>

<p>
	 
</p>

<p>
	In a running incident update log that began on May 1, Steve Proud, Instructure's chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.
</p>

<p>
	 
</p>

<p>
	The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta, and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”
</p>

<p>
	 
</p>

<p>
	TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools' Canvas portals by injecting an HTML file to display their own message on the schools' Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.
</p>

<p>
	 
</p>

<p>
	The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”
</p>

<p>
	 
</p>

<p>
	Instructure did not immediately respond to a request for comment about Thursday's outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a long-standing yet endlessly escalating problem of data extortion and ransomware attacks.
</p>

<p>
	 
</p>

<p>
	The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.
</p>

<p>
	 
</p>

<p>
	In the case of Canvas, it is similarly unclear who is acting behind the ShinyHunters name. Allison Nixon, the chief research officer at cybersecurity firm Unit 221b who has closely tracked ShinyHunters and other ransomware groups, says the activity appears to be related to recent activity from a group of hackers sometimes referred to as ScatteredLapsus$Hunters.
</p>

<p>
	 
</p>

<p>
	Earlier on Thursday, a dark-web site used by hackers operating under the ShinyHunters name to threaten and extort their targets listed both Instructure and the schools that use its software as victims, along with a note from the hackers complaining that Instructure hadn’t responded to its demands to negotiate a payment. “Instructure has not even bothered speaking to us to understand the situation or to even negociate [sic] with us to prevent the release of this data,” the statement read. “The Company seemingly does not care about all the students affected and the institutions impacted by this data breach.”
</p>

<p>
	 
</p>

<p>
	By Thursday evening, however, those references to Instructure and its customers had disappeared from the site, which later became unresponsive. While ransomware gangs sometimes remove victims from their dark-web sites in response to their agreeing to pay a ransom, victims can also be removed by the hackers as a negotiating tactic, says Nixon.
</p>

<p>
	 
</p>

<p>
	“This is often one of their manipulation tactics to try to encourage the victim to pay. So while they're negotiating or after they've paid, they might take that victim off the site, or depending on how negotiations go, they might put the victim back on,” Nixon says.
</p>

<p>
	 
</p>

<p>
	She adds that, in the midst of those negotiations, Com-associated hacker groups have been known to escalate to more extreme coercive tactics to maximize the victim’s incentive to pay, including distributed denial of service attacks, flooding the company with phone calls and emails and even threatening executives’ families. “These kind of pressure tactics start to look a whole lot more just violent mafia rather than any kind of skilled hacker stuff,” Nixon says.
</p>

<p>
	 
</p>

<p>
	The hackers in fact list numerous other victims on their dark-web site that have previously been reported as ShinyHunters targets, including Amtrak, Harvard, University of Pennsylvania, Rockstar Games, Match, Hinge, and Bumble, though WIRED couldn’t confirm whether those organizations had in fact been breached by this specific subgroup of the Com. Nixon warns that the hackers behind the Canvas attack have in fact used old or recycled data to exaggerate claims of breaches in the past.
</p>

<p>
	 
</p>

<p>
	This latest attack and the disruption it has caused for schools across the country, however, are all too real—and represent a significant escalation from this particular ransomware gang. “It's noteworthy that a tiny number of repeat offenders can escalate for years to reach this point,” says Nixon. “It speaks to the systemic international issue of cybercrime and the need for governments around the world to set geopolitics aside and cooperate to stop those who extort money and prey on kids.”
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/canvas-hack-shinyhunters-ransomware-instructure/#intcid=_wired-verso-hp-trending_7e6c687b-f0a5-4f2e-e276-581822e0a555_popular4-2" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">34926</guid><pubDate>Sat, 09 May 2026 17:25:11 +0000</pubDate></item><item><title>International cyber attack disrupts swathe of universities and schools</title><link>https://nsaneforums.com/news/security-privacy-news/international-cyber-attack-disrupts-swathe-of-universities-and-schools-r34924/</link><description><![CDATA[<p>
	A cyber attack hit several universities and schools in the US, Canada and Australia, causing chaos, confusion and major disruptions amid the high stakes end-of-year season.
</p>

<p>
	 
</p>

<p>
	The hacking group ShinyHunters claimed responsibility for the attack, which caused the academic software Canvas used by thousands of schools and universities to go offline this week.
</p>

<p>
	 
</p>

<p>
	By late Thursday, the company Instructure, which owns Canvas, posted an update on its website saying that Canvas was "available for most users", but some universities were still reporting outages on Friday.
</p>

<p>
	 
</p>

<p>
	The cyber attacks targeted universities and schools across the globe, affecting an estimated 9,000 institutions.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="1422bb90-4b30-11f1-ac78-2112837ce2aa.jpg" class="ipsImage" data-ratio="75.10" height="540" width="430" src="https://ichef.bbci.co.uk/news/1024/cpsprodpb/113a/live/1422bb90-4b30-11f1-ac78-2112837ce2aa.jpg.webp" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">A ransom note demanding payment in bitcoin appeared on screens during a cyber-hacking incident on the cloud-based platform Canva. </span>
</p>

<p>
	 
</p>

<p>
	Mississippi State University announced that it was postponing Friday's final exams to allow affected students to recover any lost work.
</p>

<p>
	 
</p>

<p>
	Aubrey Palmer, a meteorology student at the university, told the BBC students had just finished a 2,900-word exam essay when a ransom note suddenly appeared on their screens.
</p>

<p>
	 
</p>

<p>
	The message read: "Shiny Hunters has breached Instructure (again)."
</p>

<p>
	 
</p>

<p>
	It threatened to release stolen data unless Canvas or the affected universities paid a ransom in bitcoin.
</p>

<p>
	 
</p>

<p>
	"My knee‑jerk reaction was that I'd been hacked myself, because that's what it looked like," Palmer said. "But then I actually read the ransom note and saw it was Canvas that had been hacked."
</p>

<p>
	 
</p>

<p>
	Palmer said the professor and dozens of other students all had the note and everyone was looking around the room in confusion.
</p>

<p>
	 
</p>

<p>
	At first, it was unclear whether their work had been saved.
</p>

<p>
	 
</p>

<p>
	Frustration quickly spread among the students, and Palmer said people became "so angry at the idea of having to redo" their exams.
</p>

<p>
	 
</p>

<p>
	The university has since been updating students by email, rescheduling exams, and advising them to ignore suspicious messages while responding to what it described as a "nationwide security incident".
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="51a48a80-4b2f-11f1-bd52-e755d604ece4.jpg" class="ipsImage" data-ratio="75.10" height="480" width="720" src="https://ichef.bbci.co.uk/news/1024/cpsprodpb/29b0/live/51a48a80-4b2f-11f1-bd52-e755d604ece4.jpg.webp" />
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<span style="font-size:12px;">The University of Sydney told students on Friday "Canvas was unavailable" and instructed students not to attempt to log in.</span>
</p>

<p>
	 
</p>

<p>
	"We are one of approximately 9000 institutions around the world that are impacted by this outage, and we are still waiting for advice from Instructure," the university wrote on its website.
</p>

<p>
	 
</p>

<p>
	The outage affected students' coursework and examinations, the university said, acknowledging "how disruptive this is at a critical time in the semester".
</p>

<p>
	 
</p>

<p>
	On Thursday, Idaho State University said it had cancelled exams scheduled after 12:00 local time (18:00 GMT).
</p>

<p>
	 
</p>

<p>
	Penn State University wrote in a message to students on Thursday that "no one has access" to Canvas, adding that a "resolution" was unlikely to arrive "within the next 24 hours". The university cancelled some exams scheduled for Thursday and Friday.
</p>

<p>
	 
</p>

<p>
	In an update on Thursday evening, the University of British Columbia in Vancouver informed students that Canvas was "unavailable due to a cyber breach of its parent company Instructure", and advised them to log out immediately.
</p>

<p>
	 
</p>

<p>
	The University of Toronto also reported it was impacted by the breach, saying that "multiple universities were affected".
</p>

<p>
	 
</p>

<p>
	Students at the University of California Los Angeles struggled to submit assignments online through the Canvas platform, and the University of Chicago, in Illinois, temporarily disabled its Canvas page after reports that it was targeted.
</p>

<p>
	<br />
	The Chicago Maroon, the university-led newspaper, posted a screenshot of a message from ShinyHunters that appeared to be seeking a ransom.
</p>

<p>
	 
</p>

<p>
	The message encouraged the university to contact the hacking group privately "to negotiate a settlement" and avoiding "the release of their data".
</p>

<p>
	 
</p>

<p>
	It was the same message that Northwestern University masters student Jacques Abou-Rizk said he received when he clicked a link in an email that appeared to be from a university administrator.
</p>

<p>
	 
</p>

<p>
	"I didn't know what was happening," Abou-Rizk recalled. "It's a scary message to receive."
</p>

<p>
	 
</p>

<p>
	He said the university addressed the issue on Thursday, sending a generic email, seen by the BBC, that said Northwestern was "monitoring an issue".
</p>

<p>
	 
</p>

<p>
	The email stated the university did not have an estimated restoration time for Canvas and that other IT infrastructure had not been affected.
</p>

<p>
	 
</p>

<p>
	Abou-Rizk said he was still unable to access Canvas on Friday and has not heard from the university since.
</p>

<p>
	 
</p>

<p>
	"There's definitely anxiety surrounding not only being able to complete my work and access the sites that I need access to on Canvas," Abou-Rizk said. "But also just not knowing exactly what the threat is and how it might affect me.
</p>

<p>
	 
</p>

<p>
	"I don't know what data will be released, and that scares me."
</p>

<p>
	 
</p>

<p>
	The BBC has contacted Northwestern University for comment.
</p>

<p>
	 
</p>

<p>
	ShinyHunters has been linked to several high‑profile cyber attacks in the past, including a major and economically damaging hack on Jaguar Land Rover last year.
</p>

<p>
	 
</p>

<p>
	Screen shots show the targeted threats from the group began on Sunday, with deadlines given on Thursday and 12 May, Luke Connolly, a threat analyst at the cyber security firm Emisoft, told the Associated Press.
</p>

<p>
	 
</p>

<p>
	He said discussions regarding extortion payments could be ongoing.
</p>

<p>
	 
</p>

<p>
	The group would not say what it plans to do with the data it claims to have taken during the latest attack.
</p>

<p>
	 
</p>

<p>
	Cyber attacks on Thursday came the same day that the top US Senate Democrat, Chuck Schumer, sent a letter to the Trump administration urging for more defence against cyber risks in the age of rapidly developing AI.
</p>

<p>
	 
</p>

<p>
	The Department of Homeland Security - the agency that helps ward off against cyber attacks - "must immediately help states and localities", Schumer wrote.
</p>

<p>
	 
</p>

<p>
	"Before Americans are hit with outages, disruptions, and attacks that could put lives and livelihoods at risk," he continued. 
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.bbc.com/news/articles/ce3pq0136eqo" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">34924</guid><pubDate>Sat, 09 May 2026 14:54:33 +0000</pubDate></item><item><title>Microsoft says passwords are no longer enough as it pushes passkeys</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-says-passwords-are-no-longer-enough-as-it-pushes-passkeys-r34916/</link><description><![CDATA[<h3>
	Microsoft claims regular passwords are no longer enough. As attacks use more sophisticated AI tools, the company pushes passkeys.
</h3>

<p class="img-center">
	<img alt="Passkey settings in Windows 11" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/05/1778237967_passkeys.webp">
</p>

<p>
	On World Password Day, the first Thursday of May, Microsoft published a blog post detailing the importance of shifting from traditional passwords to passkeys as security becomes more important amid more advanced attacks using AI and other sophisticated techniques.
</p>

<p>
	 
</p>

<p>
	In a new security blog post, the company says passkeys are becoming increasingly important. According to Microsoft, passwords remain one of the weakest links in online security. With credential leaks and phishing attacks, Microsoft argues that users should ditch traditional passwords and switch to passkeys.
</p>

<p>
	 
</p>

<p>
	Microsoft is already a major passkey proponent. Earlier this year, the company announced that new Microsoft accounts are now passwordless by default, allowing users to sign in with passkeys, biometrics, or security keys instead of traditional passwords. Existing users can also remove passwords from their accounts manually. Additionally, Windows 11 now has better passkey integration, which allows it to <a href="https://www.neowin.net/news/microsoft-adds-native-support-for-1password-and-bitwarden-passkeys-in-windows-11/" rel="external nofollow">use passkeys stored in third-party managers</a> like 1Password or Bitwarden. Microsoft will also let you sync passkeys from Microsoft Password Manager to iOS and Android via the Edge browser.
</p>

<p>
	 
</p>

<p>
	Passkeys offer a simpler and more secure authentication method because they rely on device-based verification, such as fingerprints, facial recognition, or PINs. Unlike passwords, passkeys are resistant to phishing attacks and cannot be easily stolen through fake login pages.
</p>

<p>
	 
</p>

<p>
	Microsoft is not alone in this effort either. The wider tech industry, including members of the FIDO Alliance, has been heavily promoting passkey adoption over the last year as part of a broader push toward passwordless authentication. As such, the FIDO Alliance estimates that 5 billion passkeys are already in use worldwide. Microsoft adds that "hundreds of millions of users" have already switched to passkeys for OneDrive, Xbox, and other Microsoft-made consumer services. The company itself switched its environment to passkeys:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Inside Microsoft, we’ve eliminated weaker authentication methods and rolled out phishing-resistant authentication, covering 99.6% of users and devices in our environment. It’s made signing in a lot simpler: no codes to enter, no extra prompts to manage, just a straightforward experience for everyone.
	</p>
</blockquote>

<p>
	Microsoft also wants to make sure bad actors cannot phish out your account recovery data. Starting January 2027, security questions will no longer be able to reset Microsoft Entra ID passwords.
</p>

<p>
	 
</p>

<p>
	You can read more about the company's password-less efforts in <a href="https://www.microsoft.com/en-us/security/blog/2026/05/07/world-passkey-day-advancing-passwordless-authentication/" rel="external nofollow">a post on the official blog</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-says-passwords-are-no-longer-enough-as-it-pushes-passkeys/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 9 May 2026 at 7:15 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34916</guid><pubDate>Fri, 08 May 2026 21:16:18 +0000</pubDate></item><item><title>If you downloaded this popular software recently, you might have installed malware</title><link>https://nsaneforums.com/news/security-privacy-news/if-you-downloaded-this-popular-software-recently-you-might-have-installed-malware-r34910/</link><description><![CDATA[<p>
	<span style="font-size:14px;"><strong>Hackers exploited an unpatched security vulnerability on JDownloader's website and used it to serve malware-laced downloads.</strong></span>
</p>

<p>
	 
</p>

<p>
	The website for the popular download manager, JDownloader, has been compromised by attackers who spent over a day serving malicious installers to Windows and Linux users, replacing the legitimate download files with malware.
</p>

<p>
	 
</p>

<p>
	The JDownloader team first confirmed the hack yesterday and immediately took down the website for a full investigation. The action came after a user on Reddit reported that fresh downloads were being flagged by Windows SmartScreen and listed a suspicious publisher, as one "Zipline LLC", instead of the expected "AppWork" signature. The user's post quickly gained traction and prompted a developer from the team to step in and confirm the breach.
</p>

<p>
	 
</p>

<p>
	The JDownloader team<span> </span><a href="https://old.reddit.com/r/jdownloader/comments/1t6goqe/is_the_website_hacked/okhg2ur/" rel="external nofollow">said</a><span> </span>that its initial investigation confirmed a limited but serious breach. The attackers specifically modified the alternative download page on May 6. They replaced all the alternative Windows installer links with their own malicious, unsigned executables.
</p>

<p>
	 
</p>

<p>
	The Linux shell installer was also swapped with a version containing malicious shell code. However, the team was quick to reassure users that the main JDownloader.jar file, macOS installers, and packages from repositories like Winget, Flatpak, and Snap were never compromised. Those packages rely on separate infrastructure secured with checksums, and in-app updates are protected by end-to-end digital signatures.
</p>

<p>
	 
</p>

<p>
	The attackers were able to gain access thanks to an "unpatched" security bug on the website. This flaw lets them alter the site's Access Control Lists without needing to be authenticated. After giving themselves edit rights, they simply replaced the official download links with their own. Reports from users who ran the infected files are pretty grim, with some stating the malware disabled Windows Defender entirely.
</p>

<p>
	 
</p>

<p>
	JDownloader is the latest victim of a supply chain-style attack using the popularity of a trusted utility to deliver malware. Just last month, hackers<span> </span><a href="https://www.neowin.net/news/cpu-z-and-hwmonitor-downloads-tampered-with-by-hackers-in-new-supply-chain-style-attack/" rel="external nofollow">breached the official website</a><span> </span>for CPUID (the maker of the popular hardware diagnostic tools CPU-Z and HWMonitor) and served a deceptively named file (HWiNFO_Monitor_Setup.exe) that tripped Windows Defender.
</p>

<p>
	 
</p>

<p>
	For CPU-Z, the hackers bundled a malicious, Zig-compiled file named CRYPTBASE.dll with the otherwise clean CPU-Z application, so that when you run it, the program unknowingly loads the fake, malicious DLL file into its memory space first. After a Reddit user raised the alarm, CPUID quickly took down the website, patched the API vulnerability, and restored the clean download links.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/if-you-downloaded-this-popular-software-recently-you-might-have-installed-malware/" rel="external nofollow">Source</a>
</p>
]]></description><guid isPermaLink="false">34910</guid><pubDate>Fri, 08 May 2026 15:45:52 +0000</pubDate></item><item><title>DAEMON Tools devs confirm breach, release malware-free version</title><link>https://nsaneforums.com/news/security-privacy-news/daemon-tools-devs-confirm-breach-release-malware-free-version-r34884/</link><description><![CDATA[<p>
	Disc Soft Limited, the maker of DAEMON Tools Lite, confirmed that the software had been trojanized in a supply chain attack and released a new, malware-free version.
</p>

<p>
	 
</p>

<p>
	"Within less than 12 hours of identifying the issue, we were able to implement a solution. Based on our current findings, the issue was limited to the free DAEMON Tools Lite version and did not affect any of our other products," Disc Soft told BleepingComputer.
</p>

<p>
	 
</p>

<p>
	"We have not identified evidence supporting claims that all DAEMON Tools users were impacted, and at this stage, we are not in a position to confirm any impact on paid versions customers. Our current analysis indicates that DAEMON Tools Pro and DAEMON Tools Ultra were not affected and absolutely safe."
</p>

<p>
	 
</p>

<p>
	In a separate statement published earlier today, Disc Soft also said it has secured its infrastructure. Still, it has yet to attribute the attack to a specific threat actor or share additional information about the breach, including the attack vector used to access its systems, as it continues to investigate the incident.
</p>

<p>
	 
</p>

<p>
	"Following an internal investigation, we identified unauthorized interference within our infrastructure. As a result, certain installation packages were impacted within our build environment and were released in a compromised state. Version 12.6 of DAEMON Tools Lite, which does not contain the suspected compromised files, was released on May 5." <a href="https://blog.daemon-tools.cc/post/security-incident" rel="external nofollow" target="_blank">the company said</a>.
</p>

<p>
	 
</p>

<p>
	"Users of other DAEMON Tools products, including paid versions of DAEMON Tools Lite, DAEMON Tools Ultra, and DAEMON Tools Pro are not affected by this incident and can continue using their software as usual."
</p>

<p>
	 
</p>

<p>
	Users who downloaded or installed DAEMON Tools Lite version 12.5.1 (free) since April 8 are advised to uninstall the app, run a full system scan using security or antivirus software, and install the latest version of DAEMON Tools Lite (12.6) from the official website.
</p>

<p>
	 
</p>

<p>
	Disc Soft has removed the trojanized version, which is no longer supported, and now displays a warning prompting users to install the latest version of DAEMON Tools Lite.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="DAEMON Tools Lite 12.5.1 warning" class="ipsImage" height="495" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2026/DAEMON%20Tools%20Lite%2012_5_1%20warning.jpg">
		<figcaption>
			<em>DAEMON Tools Lite 12.5.1 warning (<a href="https://infosec.exchange/@wdormann" rel="external nofollow" target="_blank">Will Dormann</a>)</em>
		</figcaption>
	</figure>
</div>

<p>
	As cybersecurity company Kaspersky revealed on Tuesday, <a href="https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/" rel="external nofollow" target="_blank">hackers trojanized DAEMON Tools Lite installers</a> and used them to backdoor thousands of systems from more than 100 countries that downloaded the software from the official website since April 8.
</p>

<p>
	 
</p>

<p>
	After the unsuspecting users executed the digitally signed trojanized installers (versions ranging from 12.5.0.2421 to 12.5.0.2434), the malicious code embedded in the compromised binaries deployed a payload designed to establish persistence and activate a backdoor on system startup.
</p>

<p>
	 
</p>

<p>
	The first-stage malware dropped in the attack was a basic information stealer that collected system data (including hostname, MAC address, running processes, installed software, and system locale) and sent it to attacker-controlled servers for victim profiling. Based on the results, some of the infected systems received a second stage, a lightweight backdoor that can execute commands, download files, and run code directly in memory.
</p>

<p>
	 
</p>

<p>
	In at least one case, Kaspersky observed the deployment of a QUIC RAT malware, which can inject malicious code into legitimate processes and supports multiple communication protocols.
</p>

<p>
	 
</p>

<p>
	While investigating the attack, Kaspersky found that retail, scientific, government, and manufacturing organizations in Russia, Belarus, and Thailand, as well as home users in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China, were among the victims whose devices were infected with malicious payloads.
</p>

<p>
	 
</p>

<p>
	Today, in an update to the original report, the Russian cybersecurity company confirmed that DAEMON Tools Lite 12.6.0, released yesterday, no longer exhibits malicious behavior.
</p>

<p>
	 
</p>

<p>
	"Following disclosure, the vendor acknowledged the issue and published a new version of the software to address it," Kaspersky said. "The updated DAEMON Tools version 12.6.0.2445 no longer shows the malicious behavior."
</p>

<p>
	 
</p>

<p>
	<em>Update May 06, 14:09 EDT</em>: Added Disc Soft statement.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/daemon-tools-devs-confirm-breach-release-malware-free-version/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>
<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedauthorid="113165" data-embedcontent="" data-embedid="embed6459210403" src="https://nsaneforums.com/topic/484382-daemon-tools-lite-12602445/?do=embed&amp;comment=1899045&amp;embedComment=1899045&amp;embedDo=findComment#comment-1899045" style="overflow: hidden; height: 334px; max-width: 502px;"></iframe>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 7 May 2026 at 6:59 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34884</guid><pubDate>Wed, 06 May 2026 21:01:35 +0000</pubDate></item><item><title>DAEMON TOOLS supply chain attack ongoing since April, thousands affected</title><link>https://nsaneforums.com/news/security-privacy-news/daemon-tools-supply-chain-attack-ongoing-since-april-thousands-affected-r34878/</link><description><![CDATA[<p>
	<span style="font-size:14px;"><strong>Security researchers have identified an active supply chain compromise in DAEMON Tools installers impacting users globally since April 2026.</strong></span>
</p>

<p>
	 
</p>

<p>
	A major supply chain attack targeting the widely used disk imaging software DAEMON Tools has been uncovered, with malicious installers distributed through official channels since early April 2026. According to findings published by Kaspersky, attackers compromised legitimate installers and embedded backdoors into signed binaries, allowing malware to be delivered under the guise of trusted software updates.
</p>

<p>
	 
</p>

<p>
	The campaign began on April 8, 2026, when multiple versions of DAEMON Tools (12.5.0.2421 to 12.5.0.2434) were trojanised. The infected installers were hosted on the software’s official website and signed using valid digital certificates belonging to developer AVB Disc Soft. This made the malicious packages appear authentic, significantly increasing the likelihood of successful infection. Researchers say the attack remains active as of early May, with infrastructure still operational.
</p>

<p>
	 
</p>

<p>
	Several core binaries, including DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe, were modified to include a hidden backdoor. Once installed, these components execute automatically at system startup and establish communication with an external command-and-control server. The attackers also used a domain designed to resemble legitimate DAEMON Tools website, further blending malicious activity with normal traffic. The malicious domain was registered just days before the campaign began, suggesting a carefully planned operation.
</p>

<p>
	 
</p>

<p>
	The attack follows a staged structure. In most cases, infected systems first receive an information-stealing payload that gathers system data such as MAC addresses, hostnames, installed software, running processes, network configuration, and system locale. This information is then sent to attacker-controlled servers and is likely used to profile compromised systems and assess their value for further exploitation. Interestingly, parts of this payload contain Chinese-language strings, hinting at a possible Chinese-speaking threat actor; however, no formal attribution has been made.
</p>

<p>
	 
</p>

<p>
	Despite thousands of infections observed globally, only a small subset of infected machines received additional malware beyond the initial payload. These higher-value targets were associated with organisations operating in the government, manufacturing, scientific research, and retail sectors. The selective nature of this deployment suggests that the operation was not purely opportunistic, but instead involved targeted objectives consistent with espionage or strategic intrusion activity.
</p>

<p>
	 
</p>

<p>
	Among the second-stage tools identified was a minimalistic backdoor capable of executing commands, downloading files, and running code directly in memory. In at least one confirmed case, a more advanced implant known as QUIC RAT was deployed. This malware supports multiple communication protocols, including HTTP, TCP, DNS, and QUIC, and can inject code into legitimate processes such as notepad.exe.
</p>

<p>
	 
</p>

<p>
	Telemetry data shows thousands of infection attempts across more than 100 countries. The highest number of affected systems was recorded in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Around ten percent of affected systems belonged to organisations, while most systems only received the initial data-collection stage.
</p>

<p>
	 
</p>

<p>
	Security tools from Kaspersky reportedly detect the malicious activity at multiple stages, including suspicious PowerShell-based downloads, malware execution from temporary directories, code injection into legitimate processes, and unusual outbound network traffic.
</p>

<p>
	 
</p>

<p>
	Organisations are advised to carry out audits of systems where DAEMON Tools was installed after 8 April 2026. It is also recommended to monitor systems for unusual command-line activity, particularly involving PowerShell. In addition, organisations are encouraged to implement zero-trust security models and restrict execution from temporary directories.
</p>

<p>
	 
</p>

<p>
	The<span> </span><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" rel="external nofollow">DAEMON Tools compromise</a><span> </span>demonstrates how attackers continue to refine supply chain tactics, combining large-scale distribution with precise targeting. With trusted software increasingly becoming an entry point for advanced threats, organisations must treat even legitimate applications as potential risk vectors and adopt layered, proactive defence strategies.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/daemon-tools-supply-chain-attack-ongoing-since-april-thousands-affected/" rel="external nofollow">Source</a>
</p>
]]></description><guid isPermaLink="false">34878</guid><pubDate>Wed, 06 May 2026 11:16:40 +0000</pubDate></item><item><title>Edge may reportedly leak all your passwords easily and Microsoft says it's "by design"</title><link>https://nsaneforums.com/news/security-privacy-news/edge-may-reportedly-leak-all-your-passwords-easily-and-microsoft-says-its-by-design-r34867/</link><description><![CDATA[<h3>
	Edge stores passwords in plaintext memory at startup; a tool has been released to test against the flaw.
</h3>

<p>
	A cybersecurity researcher has released a proof-of-concept (PoC) tool highlighting how saved passwords are handled in Microsoft Edge. The researcher, known online as Tom Jøran Sønstebyseter Rønning, shared his findings on social media handles like X alongside a working demonstration.
</p>

<p>
	 
</p>

<p>
	According to the post, Microsoft Edge loads saved user credentials into system memory in plaintext at startup, even when those credentials are not actively in use. And the browser still asks you to log in again while it holds all the passwords unprotected in RAM.
</p>

<p>
	 
</p>

<p>
	To explain the behavior, the researcher published a tool on GitHub titled “EdgeSavedPasswordsDumper.” The project is described as an educational utility designed to help security professionals and users verify how stored credentials are managed within the browser environment. The tool works by accessing the browser’s process memory, where usernames and passwords may be stored in readable form.
</p>

<p>
	 
</p>

<p>
	According to the researcher’s observations, the parent process of Microsoft Edge consistently holds decrypted credentials, making it a potential target for extraction if an attacker gains sufficient system privileges. Organisations running shared or multi-user systems may be particularly affected, as a compromised account with administrative privileges could access data from multiple active sessions.
</p>

<p>
	 
</p>

<p>
	While the technique does not represent a remote exploit on its own, it could become relevant in scenarios where an attacker already has elevated access to a system. In such cases, memory-dumping techniques like using common administrative tools could potentially expose stored login information.
</p>

<div data-oembed-url="https://x.com/L1v1ng0ffTh3L4N/status/2051308329880719730">
	<blockquote align="center" class="QuoteNewsStyle" data-dnt="true">
		<p dir="ltr" lang="en">
			Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them. <a href="https://t.co/ci0ZLEYFLB" rel="external nofollow">pic.twitter.com/ci0ZLEYFLB</a>
		</p>

		<p>
			 
		</p>
		— Tom Jøran Sønstebyseter Rønning (@L1v1ng0ffTh3L4N) <a href="https://twitter.com/L1v1ng0ffTh3L4N/status/2051308329880719730?ref_src=twsrc%5Etfw" rel="external nofollow">May 4, 2026</a>
	</blockquote>
</div>

<p>
	Interestingly, the issue appears to be specific to Edge among Chromium-based browsers as during testing, the researcher reported that alternatives such as Google Chrome and Brave did not exhibit the same behavior. The latter do it better by typically decrypting credentials only when needed rather than storing them persistently in memory. However, that's not to say that Chrome is flawless as we recently covered <a href="https://www.neowin.net/news/report-google-chrome-lacks-a-very-important-feature-microsoft-edge-firefox-brave-have/" rel="external nofollow">fingerpriting protection</a>, something which Google's browser lacks.
</p>

<p>
	 
</p>

<p>
	Bizarrely, perhaps, Microsoft has apparently categorized this behavior as “by design,” when the researcher tried to inform the company about the issue. Nothing beyond that was seemingly said by Microsoft.
</p>

<p>
	 
</p>

<p>
	<em>Thanks for the tip, <a href="https://www.neowin.net/forum/profile/50011-goretsky/" rel="external nofollow">Aryeh Goretsky</a>!!!</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/edge-may-reportedly-leak-all-your-passwords-easily-and-microsoft-says-its-by-design/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 6 May 2026 at 7:39 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34867</guid><pubDate>Tue, 05 May 2026 21:40:20 +0000</pubDate></item><item><title>Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack</title><link>https://nsaneforums.com/news/security-privacy-news/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack-r34866/</link><description><![CDATA[<h3>
	Daemon Tools users: It’s time to check your machines for stealthy infections, stat.
</h3>

<p>
	Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday.
</p>

<p>
	 
</p>

<p>
	Kaspersky, the security firm <a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" rel="external nofollow">reporting</a> the supply-chain attack, said it began on April 8 and remained active as of the time its post went live. Installers that are signed by the developer’s official digital certificate and downloaded from its website infect Daemon Tools executables, causing the malware to run at boot time. Kaspersky didn’t explicitly say so, but based on technical details, the infected versions appear to be only those that run on Windows. Versions 12.5.0.2421 through 12.5.0.2434 are affected. Neither Kaspersky nor developer AVB could be contacted immediately for additional details.
</p>

<h2>
	Hard to defend against
</h2>

<p>
	Infected versions contain an initial payload that collects MAC addresses, hostnames, DNS domain names, running processes, installed software, and system locales. The malware sends them to an attacker-controlled server. Thousands of machines in more than 100 countries were targeted. Out of the many machines infected, about 12 of them, belonging to retail, scientific, government, and manufacturing organizations, have received a follow-on payload—an indication that the supply-chain attack targets select groups.
</p>

<p>
	 
</p>

<p>
	The incident is only the latest supply-chain attack. Other such attacks include the poisoning of the <a href="https://arstechnica.com/information-technology/2017/09/ccleaner-malware-outbreak-is-much-worse-than-it-first-appeared/" rel="external nofollow">CCleaner</a> Windows utility in 2017, the <a href="https://arstechnica.com/information-technology/2020/12/russian-hackers-hit-us-government-using-widespread-supply-chain-attack/" rel="external nofollow">Solar Winds</a> app management software for enterprises in 2020, and <a href="https://arstechnica.com/information-technology/2023/03/massive-supply-chain-attack-with-ties-to-north-korea-hits-users-of-3cx-voice-app/" rel="external nofollow">3CX</a> VoIP client in 2023. Such attacks are hard to defend against because users are infected when they do nothing more than install digitally signed updates available through official channels. In all three cases it took weeks or months before the compromised update distribution channels were discovered.
</p>

<p>
	 
</p>

<p>
	“Based on our long-term experience of analyzing supply chain attacks, we can conclude that attackers orchestrated the DAEMON Tools compromise in a highly sophisticated manner,” Kaspersky researchers wrote. “For example, the time it took to detect this attack, which turned out to be about one month, is comparable to the 3CX supply chain attack which we researched together with the cybersecurity community in 2023. Given the high complexity of the attack, it is paramount for organizations to carefully examine machines that had DAEMON Tools installed, for abnormal cybersecurity-related activities that occurred on or after April 8.”
</p>

<p>
	 
</p>

<p>
	One of the follow-on payloads pushed to about a dozen organizations was what Kaspersky described as a “minimalistic backdoor.” It has the ability to execute commands, download files, and run shellcode payloads in memory—making the infection harder to detect.
</p>

<p>
	 
</p>

<p>
	Kaspersky said that it observed a more complex backdoor dubbed QUIC RAT, installed on a single machine belonging to an educational institution located in Russia. Initial analysis found that it can inject payloads into the notepad.exe and conhost.exe processes and supports a variety of C2 communication protocols, including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3.
</p>

<p>
	 
</p>

<p>
	The 100 infected organizations were primarily located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Kaspersky’s visibility into the attack is limited because it’s based solely on telemetry provided by its own products.
</p>

<p>
	 
</p>

<p>
	Kaspersky researchers wrote:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		The analysis shows that 10% of the affected systems belong to businesses and organizations. Attackers attempted to infect most of the affected machines only with the information collector payload. However, the other backdoor payload, which is more complex, has been observed only on a dozen machines of government, scientific, manufacturing and retail organizations located in Russia, Belarus and Thailand. This manner of deploying the backdoor to a small subset of infected machines clearly indicates that the attacker had intentions to conduct the infection in a targeted manner. However, their intent – whether it is cyberespionage or ‘big game hunting’ – is currently unclear.
	</p>
</blockquote>

<p>
	More recent supply-chain attacks have hit <a href="https://arstechnica.com/information-technology/2026/04/why-a-recent-supply-chain-attack-singled-out-security-firms-checkmarx-and-bitwarden/" rel="external nofollow">Trivy, Checkmarx, and Bitwarden</a> and more than <a href="https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/" rel="external nofollow">150 packages</a> available through open source repositories. Last year, there were at least <a href="150%20packages" rel="">six notable</a> such attacks.
</p>

<p>
	 
</p>

<p>
	Anyone who uses Daemon Tools should take time to scan the entirety of their machines using reputable antivirus software. Windows users should additionally check for indicators of compromise listed in the Kaspersky post. For more technically advanced users, Kaspersky recommends monitoring “suspicious code injections into legitimate system processes, especially when the source is executables launched from publicly accessible directories such as Temp, AppData, or Public.”
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 6 May 2026 at 7:38 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34866</guid><pubDate>Tue, 05 May 2026 21:39:16 +0000</pubDate></item><item><title>Google now offers up to $1.5 million for some Android exploits</title><link>https://nsaneforums.com/news/security-privacy-news/google-now-offers-up-to-15-million-for-some-android-exploits-r34865/</link><description><![CDATA[<p>
	Google overhauls its Android and Chrome vulnerability rewards programs, offering bounties of up to $1.5 million for the most difficult exploits while scaling back payouts for flaws that artificial intelligence (AI) has made easier to find.
</p>

<p>
	 
</p>

<p>
	The top reward of $1.5 million is reserved for zero-click Pixel Titan M2 security chip full-chain exploits with persistence, the most technically demanding attack scenario in the program, while the same exploits, but without persistence, are also eligible for up to $750,000.
</p>

<p>
	 
</p>

<p>
	On the Google Chrome side, full-chain browser process exploits on up-to-date operating systems and hardware now come with rewards of up to $250,000, plus an additional $250,128 bonus for successfully exploiting MiraclePtr-protected memory allocations.
</p>

<p>
	 
</p>

<p>
	"We know that certain particularly impactful exploits remain incredibly difficult to achieve and we've greatly appreciated collaborating with the researcher community to discover and unearth them," <a href="https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era" rel="external nofollow" target="_blank">Google said</a>.
</p>

<p>
	 
</p>

<p>
	"We want to build on this partnership by continuing to emphasize the highest tiers of rewards across both Android and Chrome."
</p>

<p>
	 
</p>

<p>
	For the Chrome program, Google shifts its focus to concise reports containing only bug proofs and essential artifacts, rather than lengthy written analyses that AI can now generate automatically.
</p>

<p>
	 
</p>

<p>
	The Android program will also narrow its focus to Linux kernel vulnerabilities in Google-maintained components, unless researchers can demonstrate concrete exploitability on Android devices.
</p>

<p>
	 
</p>

<p>
	"While AI has made it effortless to produce lengthy, detailed write-ups, our internal tooling has also evolved to help us automatically explain and suggest fixes for bugs," the company added.
</p>

<p>
	 
</p>

<p>
	This vulnerability rewards program restructuring follows a record year for Google's bug bounty effort, with the company <a href="https://www.bleepingcomputer.com/news/google/google-paid-171-million-for-vulnerability-reports-in-2025/" rel="external nofollow" target="_blank">paying $17.1 million</a> to 747 researchers in 2025, a more than 40 percent increase from 2024 and an all-time high.
</p>

<p>
	 
</p>

<p>
	This has brought the total payouts since the program <a href="https://security.googleblog.com/2010/11/rewarding-web-application-security.html" rel="external nofollow" target="_blank">launched in 2010</a> to more than $81.6 million, and Google estimates that the total aggregate rewards paid in 2026 will increase despite reductions in some individual reward amounts.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-now-offers-up-to-15-million-for-some-android-exploits/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 6 May 2026 at 7:37 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34865</guid><pubDate>Tue, 05 May 2026 21:38:28 +0000</pubDate></item><item><title>Microsoft Defender flagging "Cerdigent" trojan malware on Windows 11, Server PCs worldwide</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-defender-flagging-cerdigent-trojan-malware-on-windows-11-server-pcs-worldwide-r34833/</link><description><![CDATA[<h3>
	Defender flags “Cerdigent” alerts on Windows tied to DigiCert breach, involves the misuse of legitimate code-signing certs.
</h3>

<p>
	A wave of recent alerts from Microsoft Defender identifying a threat labeled “Cerdigent” on Windows systems is drawing the attention of users and security researchers worldwide, with early evidence suggesting the detections may be tied to the abuse of mis-issued digital certificates rather than a real malware campaign.
</p>

<p>
	 
</p>

<p>
	According to a report filed in Mozilla’s Bugzilla tracking system, the root of the issue lies in a security incident involving certificate authority DigiCert. The report suggests that a threat actor gained limited access to DigiCert’s internal support systems after compromising a support analyst’s machine. This access allowed the attacker to get initialisation codes for "a limited number of code signing certificates."
</p>

<p>
	 
</p>

<p>
	These codes, when combined with approved orders, were sufficient to generate legitimate code-signing certificates that were used to sign software so that they appear trustworthy to operating systems like Windows and anti-virus products like Defender.
</p>

<p class="img-center">
	<img alt="Cerdigent trojan malware detected on Defender" class="ipsImage" height="450" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/05/1777823171_windows_defender_cerdigent_malware.webp">
</p>

<p>
	DigiCert investigated and found and revoked 60 certificates as they were being used by the Zhong stealer malware. In its full incident report on Bugzilla DigiCert explained: "During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor's actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:
</p>

<p>
	 
</p>

<ul>
	<li>
		DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
	</li>
	<li>
		DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
	</li>
	<li>
		GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
	</li>
	<li>
		Verokey High Assurance Secure Code EV
	</li>
</ul>

<p>
	 
</p>

<p>
	27 of the revoked certificates were explicitly linked to the threat actor (11 were identified in certificate problem reports provided to DigiCert by community members linking the certificates to malware, and 16 were identified during our own investigation). ... In addition to the 27 identified above, 33 of the 60 total certificates were revoked during our own investigation as a precautionary measure. ... The exploited certificates identified by the community member were found to have been used to sign the "Zhong Stealer" malware family."
</p>

<p>
	 
</p>

<p>
	Thus for now, available information suggests that many Cerdigent alerts may not indicate active infection but a false alarm. Microsoft's own threat database does not say much about it except that "Cerdigent.A!dha can perform a number of actions of a malicious actor's choice on your device."
</p>

<p>
	 
</p>

<p>
	Since code-signing certificates play a key role in the trust model of modern operating systems, when compromised, they can blur the line between legit and malicious software. If you are encountering such warnings then you are advised to monitor updates from security vendors, as signature corrections are often issued quickly in cases of widespread false positives, which seems to be case here too.
</p>

<p>
	 
</p>

<p>
	Source: <a automate_uuid="0faf46a7-59d3-4f41-90c2-4b0d08b8c7ba" href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033170" rel="external nofollow">Bugzilla@Mozilla</a>
</p>

<p>
	 
</p>

<p>
	<em>Thanks for the tip, <a automate_uuid="98f7f273-58ac-40df-b9ac-1e8de0700b55" href="https://www.neowin.net/forum/profile/50011-goretsky/" rel="external nofollow">Aryeh Goretsky</a>!!!</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-defender-flagging-cerdigent-trojan-malware-on-windows-11-server-pcs-worldwide/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Monday 4 May 2026 at 7:26 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34833</guid><pubDate>Sun, 03 May 2026 21:27:18 +0000</pubDate></item><item><title>The most severe Linux threat to surface in years catches the world flat-footed</title><link>https://nsaneforums.com/news/security-privacy-news/the-most-severe-linux-threat-to-surface-in-years-catches-the-world-flat-footed-r34796/</link><description><![CDATA[<h3>
	CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.
</h3>

<p>
	Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices.
</p>

<p>
	 
</p>

<p>
	The vulnerability and exploit code that exploits it were <a href="https://copy.fail/#contact" rel="external nofollow">released Wednesday evening</a> by researchers from security firm Theori, five weeks after privately disclosing it to the Linux kernel security team. The team patched the vulnerability in versions <a href="https://github.com/torvalds/linux/commit/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5" rel="external nofollow">7.0</a>, <a href="https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237" rel="external nofollow">6.19.12</a>, <a href="https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8" rel="external nofollow">6.18.12</a>, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254) but few of the Linux distributions had incorporated those fixes at the time the exploit was released.
</p>

<h2>
	A single script hacks all distros
</h2>

<p>
	The critical flaw, tracked as CVE-2026-31431 and the name CopyFail, is a local privilege escalation, a vulnerability class that allows unprivileged users to elevate themselves to administrators. CopyFail is particularly severe because it can be exploited with a single piece of exploit code—released in Wednesday’s disclosure—that works across all vulnerable distributions with no modification. With that, an attacker can, among other things, hack multi-tenant systems, break out of containers based on Kubernetes or other frameworks, and create malicious pull requests that pipe the exploit code through <a href="https://en.wikipedia.org/wiki/CI/CD" rel="external nofollow">CI/CD</a> work flows.
</p>

<p>
	 
</p>

<p>
	“‘Local privilege escalation’ sounds dry, so let me unpack it,” researcher Jorijn Schrijvershof <a href="https://jorijn.com/en/blog/copy-fail-cve-2026-31431-linux-kernel-bug-explained/" rel="external nofollow">wrote Thursday</a>. “It means: an attacker who already has some way to run code on the machine, even as the most boring unprivileged user, can promote themselves to root. From there they can read every file, install backdoors, watch every process, and pivot to other systems.”
</p>

<p>
	 
</p>

<p>
	Schrijvershof added that the same Python script Theori released works reliably for Ubuntu 22.04, Amazon Linux 2023, SUSE 15.6, and Debian 12. The researcher continued:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Why does that matter on shared infrastructure? Because “local” covers a lot of ground in 2026: every container on a shared Kubernetes node, every tenant on a shared hosting box, every CI/CD job that runs untrusted pull-request code, every WSL2 instance on a Windows laptop, every containerised AI agent given shell access. They all share one Linux kernel with their neighbours. A kernel LPE collapses that boundary.
	</p>

	<p>
		 
	</p>

	<p>
		The realistic threat chain looks like this. An attacker exploits a known WordPress plugin vulnerability and gets shell access as www-data. They run the copy.fail PoC. They are now root on the host. Every other tenant is suddenly reachable, in the way I walked through in this hack post-mortem. The vulnerability does not get the attacker onto the box; it changes what happens in the next ten seconds after they land there.
	</p>
</blockquote>

<p>
	The vulnerability stems from a “straight-line” logic flaw in the kernel’s crypto API. Many exploits exploiting <a href="https://portswigger.net/web-security/race-conditions" rel="external nofollow">race conditions</a> and memory corruption flaws don’t consistently succeed across kernel versions or distributions, and sometimes even on the same machine. Because the code released for CopyFail exploits a logic flaw, “reliability isn’t probabilistic, and the same script works across distributions, researchers from Bugcrowd <a href="https://www.bugcrowd.com/blog/what-we-know-about-copy-fail-cve-2026-31431/" rel="external nofollow">wrote</a>. “No race window, no kernel offset.”
</p>

<p>
	 
</p>

<p>
	CopyFail gets its name because the authencesn AEAD template process (used for IPsec extended sequence numbers) doesn’t actually copy data when it should. Instead, it “uses the caller’s destination buffer as a scratch pad, scribbles 4 bytes past the legitimate output region, and never restores them,” Theori said. “The ‘copy’ of the AAD ESN bytes ‘fails’ to stay inside the destination buffer.”
</p>

<h2>
	The worst Linux vulnerability in years
</h2>

<p>
	Other security experts echoed the perspective that CopyFail poses a serious threat, with one <a href="https://seclists.org/oss-sec/2026/q2/283" rel="external nofollow">saying</a> it’s the “worst make-me-root vulnerabilities in the kernel in recent times.”
</p>

<p>
	 
</p>

<p>
	The most recent such Linux vulnerability was <a href="https://arstechnica.com/information-technology/2022/03/linux-has-been-bitten-by-its-most-high-severity-vulnerability-in-years/" rel="external nofollow">Dirty Pipe</a> from 2022 and <a href="https://arstechnica.com/information-technology/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/" rel="external nofollow">Dirty Cow</a> in 2016. Both of those vulnerabilities were <a href="https://nvd.nist.gov/vuln/detail/cve-2022-0847" rel="external nofollow">actively exploited</a> in the wild.
</p>

<p>
	 
</p>

<p>
	Linux distributors frequently stick with older kernel versions and backport fixes into them. There’s no indication in the disclosure deadline that Theori ever contacted the distributors. With the exploit available before fixed distributions were available, the disclosure amounts to something very similar to a zero-day vulnerability being dropped, although the stiffer term is probably “zero-day patch gap.”
</p>

<p>
	 
</p>

<p>
	“The org doing the disclosure… did an absolutely terrible job of vulnerability coordination,” <a href="https://infosec.exchange/@wdormann/" rel="external nofollow">Will Dormann</a>, a senior principal vulnerability analyst at Tharros Labs, said in an interview. “What is mind boggling to me is that in their writeup they both: A) list 4 affected vendors, and <img alt="B)" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/cool.png" title="B)"> tell readers to apply vendor patches. But before firing away with the publication, they didn’t bother to see if ANY of the vendors that they list ACTUALLY HAVE PATCHES. (None do).”
</p>

<p>
	 
</p>

<p>
	Theori representatives did not respond when asked to comment.
</p>

<p>
	 
</p>

<p>
	Distributions known to have patched the vulnerability included <a href="https://ubuntu.com/security/CVE-2026-31431" rel="external nofollow">Arch Linux</a> and <a href="https://bugzilla.redhat.com/show_bug.cgi?id=2460538" rel="external nofollow">RedHat Fedora</a>. Those known to have released mitigation guidance at the time this post went live include:
</p>

<p>
	 
</p>

<ul>
	<li>
		<a href="https://www.suse.com/security/cve/CVE-2026-31431.html" rel="external nofollow">SUSE</a>
	</li>
	<li>
		<a href="https://access.redhat.com/security/cve/cve-2026-31431" rel="external nofollow">RedHat</a>
	</li>
	<li>
		<a href="https://ubuntu.com/security/CVE-2026-31431" rel="external nofollow">Ubuntu</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	People seeking the status of other distributions should check with the respective vendors.
</p>

<p>
	 
</p>

<p>
	Theori said that it discovered the vulnerability after its researcher, Taeyang Lee, found surface area in the crypto subsystem (specifically, splice() hands page-cache pages and scatterlist page provenance) had been underexplored. Using its AI-powered <a href="https://xint.io/products/xint-code" rel="external nofollow">Xint code</a> security tool, the researchers then found the bug after about an hour of scan time. The company said it has also developed an exploit that uses CopyFail to break out of Kubernetes containers.
</p>

<p>
	 
</p>

<p>
	The severity of the threat posed by CopyFail and the likelihood of active exploitation is high enough to warrant all Linux users to investigate their systems immediately. Individual distributors provide useful mitigation guidance, as does the post by Schrijvershof linked above.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 1 May 2026 at 12:12 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of April) 1,700</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34796</guid><pubDate>Fri, 01 May 2026 02:14:04 +0000</pubDate></item><item><title>UK government ignores data leak warnings as MPs back online digital checkpoints</title><link>https://nsaneforums.com/news/security-privacy-news/uk-government-ignores-data-leak-warnings-as-mps-back-online-digital-checkpoints-r34771/</link><description><![CDATA[<h3>
	The Open Rights Group warns that the Children and Schools Wellbeing Bill will force millions to hand over personal data to access everyday services.
</h3>

<p>
	The digital liberties organization, Open Rights Group, has warned that the UK government is risking the creation of a system of digital checkpoints. The warning comes after MPs backed the Children and Schools Wellbeing Bill that seeks to expand age identification across online platforms, rather than just to prevent access to adult content.
</p>

<p>
	 
</p>

<p>
	ORG <a automate_uuid="84507887-920a-474c-89a6-5c45a235ef36" href="https://www.openrightsgroup.org/press-releases/papers-please-mps-back-mass-online-digital-id-checkpoints/" rel="external nofollow">said</a> that as age identification expands, millions more people will have to hand over personal data to access everyday services. Concerns center on weak safeguards for user data, data reuse, and the possibility of fraud if user data is stolen. Just this week, medical information of over 500,000 participants of the UK Biobank science programme was found for sale on China’s Alibaba–and it’s not the only incident of data loss related to the UK government.
</p>

<p>
	 
</p>

<p>
	James Baker, Platform Power Programme Manager at ORG, said that in less than a year, the UK has gone from checking IDs for porn to the prospect of checking ID to access social media or unlock features such as livestreams or algorithmic feeds. He also pointed to this <a automate_uuid="2d733a1c-21e8-467b-950f-924e591f5b70" href="https://uk.news.yahoo.com/most-australian-teens-admit-social-111400429.html" rel="external nofollow">news story</a> showing that government-mandated social media bans like those seen in Australia are being sidestepped with face masks and their parents’ ID.
</p>

<p>
	 
</p>

<p>
	Another worry held by groups like ORG is that children will start using more seedy platforms that don’t enforce checks and potentially connect children and pedophiles in <a automate_uuid="afbe2904-64e2-467c-b5ab-a1d512fabdd4" href="https://www.neowin.net/news/telegram-faces-uk-ban-threat-as-ofcom-launches-massive-safety-investigation/" rel="external nofollow">unregulated chats</a>. This is the type of argument we’ve <a automate_uuid="bfec6c37-d2ef-4d30-8685-1ab42eb35809" href="https://www.reuters.com/world/asia-pacific/australian-pm-albanese-says-social-media-firms-now-have-responsibility-protect-2024-11-28/" rel="external nofollow">heard peddled by Big Tech</a>, which says it already has safeguards in place.
</p>

<p>
	 
</p>

<p>
	After a decade and a half of social media companies basically doing whatever they want with little oversight, and the negative social consequences this has caused such as radicalization, mental health crises, and child exploitation, it is extremely unlikely that the UK government, or any other for that matter, are going to seriously consider this view. In fact, many governments globally are now taking much tougher action against Big Tech after <a automate_uuid="f663f12b-084b-4cae-b6f1-bff2ac8d8a94" href="https://www.neowin.net/news/starmer-slams-tech-giants-as-uk-prepares-a-major-crackdown-on-social-media-child-safety/" rel="external nofollow">some countries</a> have shown<a automate_uuid="e5ee157b-f82b-4bfc-89b1-0efa49e8c354" href="https://www.neowin.net/news/australia-adds-twitch-to-its-teen-social-media-ban/" rel="external nofollow"> it can be done</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/uk-government-ignores-data-leak-warnings-as-mps-back-online-digital-checkpoints/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 29 April 2026 at 5:25 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34771</guid><pubDate>Wed, 29 Apr 2026 07:25:49 +0000</pubDate></item><item><title>Australia pushes Google and Meta to pay local media outlets for their news</title><link>https://nsaneforums.com/news/security-privacy-news/australia-pushes-google-and-meta-to-pay-local-media-outlets-for-their-news-r34754/</link><description><![CDATA[<h3>
	If tech firms fail to reach agreements with local publishers, they could face fines of up to 2.25% of their local revenue.
</h3>

<p>
	The Australian government has introduced a new bill that would require Google, Meta, and TikTok to pay fees to local news outlets for content that appears on their platforms. The bill is intended to support local media and journalism in the country.
</p>

<p>
	 
</p>

<p>
	The News Bargaining Incentive, <a automate_uuid="bda88978-cbf3-4787-884a-858963dc27cb" href="https://www.neowin.net/news/australia-to-make-tech-giants-pay-for-using-news-content-from-local-media-publishers/" rel="external nofollow">first initiated in 2024</a>, aims to end tech companies’ free use of news produced by local media outlets and ensure they pay for the content that fuels their platforms. Companies that fail to reach agreements with local news organizations could face fines of up to 2.25% of their local revenue, which could amount to millions of dollars.
</p>

<p>
	 
</p>

<p>
	"People are increasingly getting their news directly from Facebook, from TikTok and from Google, and we believe it's only fair that large digital platforms contribute to the hard work of journalism that enriches their feeds and that drives their revenue," Australia Communications Minister Anika Wells said.
</p>

<p>
	 
</p>

<p>
	Wells also suggested that tech firms strike deals with news outlets; otherwise, they may have to pay higher fines. The proposed levy would take effect on July 1. It would also apply to companies that hold a significant share of Australia's online search market and generate up to A$250 million ($179.3 million) in local revenue. The bill does not include artificial intelligence platforms, but it does apply to companies such as Google, Meta, and TikTok.
</p>

<p>
	 
</p>

<p>
	Executives from some of Australia’s largest media outlets called the latest initiative a “critical step toward securing the future of Australian news,” adding that “If digital platforms fail to pay for the use of the news content from which they profit, then journalism becomes unsustainable.”
</p>

<p>
	 
</p>

<p>
	Australia is not the first country to try to make tech firms pay for the news they use on their platforms. <a automate_uuid="d41d9a2a-0344-4fa5-9dd0-7204c7368927" href="https://www.neowin.net/news/google-agrees-to-pay-canada-100-million-cad-per-year-to-comply-with-its-online-news-act/" rel="external nofollow">Google previously paid nearly $100 million to Canadian news outlets</a> to be exempt from the Online News Act.
</p>

<p>
	 
</p>

<p>
	Via: <a automate_uuid="29dd5f37-b872-412f-8a98-d736925318eb" href="https://www.reuters.com/business/media-telecom/australia-charge-big-tech-companies-2-levy-unless-they-strike-local-news-deals-2026-04-28/" rel="external nofollow">Reuters</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/australia-pushes-google-and-meta-to-pay-local-media-outlets-for-their-news/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 29 April 2026 at 7:28 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34754</guid><pubDate>Tue, 28 Apr 2026 21:28:57 +0000</pubDate></item><item><title>Open source package with 1 million monthly downloads stole user credentials</title><link>https://nsaneforums.com/news/security-privacy-news/open-source-package-with-1-million-monthly-downloads-stole-user-credentials-r34748/</link><description><![CDATA[<h3>
	If you’re one of millions using element-data, it’s time to check for compromise.
</h3>

<p>
	Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a vulnerability in the developers’ account workflow that gave access to its signing keys and other sensitive information.
</p>

<p>
	 
</p>

<p>
	On Friday, unknown attackers exploited the vulnerability to push a new version of <a href="https://github.com/elementary-data/elementary/pkgs/container/elementary" rel="external nofollow">element-data</a>, a command-line interface that helps users monitor performance and anomalies in machine-learning systems. When run, the malicious package scoured systems for sensitive data, including user profiles, warehouse credentials, cloud provider keys, API tokens, and SSH keys, developers <a href="https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3" rel="external nofollow">said</a>. The malicious version was tagged as 0.23.3 and was published to the developers’ Python Package Index and Docker image accounts. It was removed about 12 hours later, on Saturday. Elementary Cloud, the Elementary dbt package, and all other CLI versions weren’t affected.
</p>

<h2>
	Assume compromise
</h2>

<p>
	“Users who installed 0.23.3, or who pulled and ran the affected Docker image, should assume that any credentials accessible to the environment where it ran may have been exposed,” the developers wrote.
</p>

<p>
	 
</p>

<p>
	The threat actor gained access to the developers’ account by exploiting a vulnerability in a GitHub action they created. By posting malicious code to a pull request, the attackers were able to run a bash script that ran inside the developer’s account. The bash script retrieved the sensitive data. With the account tokens and signing keys, the attacker went on to publish a malicious element-data package that was nearly indistinguishable from a legitimate one.
</p>

<p>
	 
</p>

<p>
	The developers learned of the compromise from a third-party <a href="https://github.com/elementary-data/elementary/issues/2205" rel="external nofollow">issue report</a>. Within three hours, the package was removed. Element developers said they also rotated all credentials that the malicious code had access to. They have further fixed the vulnerability and audited all their other GitHub actions to ensure none contain the same flaw.
</p>

<p>
	 
</p>

<p>
	The developers are urging all developers who installed version 0.23.3 to take the following steps immediately:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		1. Check your installed version:
	</p>

	<p>
		 
	</p>

	<p>
		<code>pip show elementary-data | grep Version</code>
	</p>

	<p>
		 
	</p>

	<p>
		2. If the version is 0.23.3, uninstall it and replace it with the safe version:
	</p>

	<p>
		 
	</p>

	<p>
		<code>pip uninstall elementary-data</code>
	</p>

	<p>
		 
	</p>

	<p>
		<code>pip install elementary-data==0.23.4</code>
	</p>

	<p>
		 
	</p>

	<p>
		In your requirements and lockfiles, pin explicitly to elementary-data==0.23.4.
	</p>

	<p>
		 
	</p>

	<p>
		3. Delete your cache files to avoid any artifacts.
	</p>

	<p>
		 
	</p>

	<p>
		4. Check for the malware’s marker file on any machine where the CLI may have run: If this file is present, the payload executed on that machine.
	</p>

	<p>
		 
	</p>

	<p>
		<code>macOS / Linux: /tmp/.trinny-security-update</code>
	</p>

	<p>
		 
	</p>

	<p>
		<code>Windows: %TEMP%\\.trinny-security-update</code>
	</p>

	<p>
		 
	</p>

	<p>
		5. Rotate any credentials that were accessible from the environment where 0.23.3 ran – dbt profiles, warehouse credentials, cloud provider keys, API tokens, SSH keys, and the contents of any .env files. CI/CD runners are especially exposed because they typically have broad sets of secrets mounted at runtime.
	</p>

	<p>
		 
	</p>

	<p>
		6. Contact your security team to hunt for unauthorized usage of exposed credentials. The relevant IOCs are <a href="https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3" rel="external nofollow">at the bottom of this post</a>.
	</p>
</blockquote>

<p>
	Over the past decade, supply-chain attacks on open source repositories have become increasingly common. In some cases, they have achieved a chain of compromises as the malicious package leads to breaches of users and, from there, breaches resulting from the compromise of the users’ environments.
</p>

<p>
	 
</p>

<p>
	HD Moore, a hacker with more than four decades of experience and the founder and CEO of runZero, said that user-developed repository workflows, such as GitHub actions, are notorious for hosting vulnerabilities.
</p>

<p>
	 
</p>

<p>
	It’s a “a major problem for open source projects with open repos,” he said. “It’s really hard to not accidentally create dangerous workflows that can be exploited by an attacker’s pull request.”
</p>

<p>
	 
</p>

<p>
	He said <a href="https://github.com/zizmorcore/zizmor" rel="external nofollow">this package</a> can be used to check for such vulnerabilities.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentials/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 28 April 2026 at 12:49 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34748</guid><pubDate>Tue, 28 Apr 2026 02:50:46 +0000</pubDate></item><item><title>Say goodbye to passwords as UK cyber experts crown passkeys the new security king</title><link>https://nsaneforums.com/news/security-privacy-news/say-goodbye-to-passwords-as-uk-cyber-experts-crown-passkeys-the-new-security-king-r34739/</link><description><![CDATA[<h3>
	In a major shift the NCSC now urges everyone to ditch vulnerable passwords for passkeys to build a safer and simpler digital future starting today.
</h3>

<p>
	GCHQ’s National Cyber Security Centre (NCSC) has just updated its guidance. It is now recommending that <a automate_uuid="81578f18-8f2c-4816-8951-e16070f15e8b" href="https://www.neowin.net/news/microsoft-entra-id-to-auto-enable-passkey-profiles-and-synced-passkeys-in-march-2026/" rel="external nofollow">consumers should pick passkeys</a>, rather than passwords, as their first login choice across all digital services. The decision was announced on Thursday, and it is notable because the NCSC is the UK government's technical authority on cyber security.
</p>

<p>
	 
</p>

<p>
	The recommendation is a change from last year when the NCSC stopped short of endorsing adoption due to some key implementation challenges. Thanks to <a automate_uuid="593ada37-ea69-4d65-8463-b156d4751860" href="https://www.neowin.net/news/microsoft-edge-can-now-store-and-sync-passkeys-across-devices/" rel="external nofollow">progress made since then</a>, it is now recommending the technology to the public as a more secure and user-friendly login method. It also calls on businesses to use it as the default authentication option to offer to consumers.
</p>

<p>
	 
</p>

<p>
	Commenting on passkeys, Jonathan Ellison, Director of National Resilience at NCSC, <a automate_uuid="bd973508-a1e8-4a7e-9021-3c8bad735d63" href="https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future" rel="external nofollow">said</a>:
</p>

<p>
	 
</p>

<p style="margin-left:40px">
	<em>“Adopting passkeys wherever you can is a strong step towards a safer, simpler login experience and I am pleased that we can now support uptake.</em>
</p>

<p>
	 
</p>

<p style="margin-left:40px">
	<em>The headaches that remembering passwords have caused us for decades no longer need to be a part of logging in where users migrate to passkeys – they are a user-friendly alternative which provide stronger overall resilience.</em>
</p>

<p>
	 
</p>

<p style="margin-left:40px">
	<em>As we aim to accelerate the UK’s cyber defences at scale, moving to passkeys is something all of us can do to improve the security of everyday digital services and be prepared for modern and future cyber threats.”</em>
</p>

<p>
	 
</p>

<p>
	While passkeys may be stronger for the general public, they’re simply not as common as passwords yet, and likely won’t be for a very long time. For those websites that don’t support passkeys yet, the advice is to use a password manager to create a strong password and to use <a automate_uuid="b944dfd9-52ee-4afe-84c8-fd49b22abba1" href="https://www.neowin.net/news/proton-launches-free-open-source-authenticator-app/" rel="external nofollow">two-factor authentication</a>.
</p>

<p>
	 
</p>

<p>
	The UK government said last year that it would roll out passkeys for its digital services as an alternative to SMS-based verification. It expects this to save millions of pounds annually.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/say-goodbye-to-passwords-as-uk-cyber-experts-crown-passkeys-the-new-security-king/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Monday 27 April 2026 at 3:40 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34739</guid><pubDate>Mon, 27 Apr 2026 05:42:02 +0000</pubDate></item><item><title>Proton Pass is getting folders, an SSH agent, and other features later this year</title><link>https://nsaneforums.com/news/security-privacy-news/proton-pass-is-getting-folders-an-ssh-agent-and-other-features-later-this-year-r34713/</link><description><![CDATA[<h3>
	Proton says it will need to rework its cryptography model to support folders, with biometric unlock coming to the extension later this year.
</h3>

<p>
	The Proton team has released the spring and summer roadmap for their password manager, Proton Pass, bringing several improvements, like folders and a new SSH agent, among others.
</p>

<p>
	 
</p>

<p>
	Starting with folders, Proton says this feature will "require some rethinking of our cryptography model" and expects it to be available in the coming months. When it launches, you will be able to organize your credentials and notes into dedicated folders and even subfolders, and then share those specific folders just like you already can with individual items or entire vaults.
</p>

<p>
	 
</p>

<p>
	Last June, Proton rolled out support for Custom Items, allowing users to create specific templates for storing unique data formats such as Wi-Fi network credentials, passports, licenses, and, of course, SSH keys.
</p>

<p>
	 
</p>

<p>
	Now, Proton says it is working on an SSH agent that lets you use those SSH keys already stored in your vault for your actual Git and terminal workflows. This feature will bring it up to par with more established password managers like 1Password and Bitwarden, which developers have used for this exact purpose for some time. The goal is to let you authenticate SSH sessions or sign Git commits using a simple biometric prompt from the desktop app, keeping the private keys off your local disk.
</p>

<p>
	 
</p>

<p>
	The Proton Pass extension is getting support for biometric unlock, using your computer's fingerprint sensor or Face ID. The initial rollout will be limited to macOS and Chromium-based browsers, with support for more platforms and browsers to follow later. Other <a automate_uuid="823b57be-c4b4-4c80-8c13-c7cf1cc27538" href="https://proton.me/blog/pass-roadmap-spring-summer-2026" rel="external nofollow">updates</a> Proton is making to the extension include adding iFrame autofill support to handle login forms embedded on complicated sites, like banking portals, and a full offline mode.
</p>

<p>
	 
</p>

<p>
	<a automate_uuid="388369fa-1486-4fa0-a4bf-887e6e8b521d" href="https://www.neowin.net/news/proton-launches-its-password-manager-proton-pass-now-available-for-download/" rel="external nofollow">Since its launch</a> in mid-2023, Proton has been aggressively pushing updates to Proton Pass. Throughout 2024 and 2025, the password manager got neat features like full passkey support, dedicated desktop apps for <a automate_uuid="66d461ef-55f3-473a-abc6-0644452ade0b" href="https://www.neowin.net/news/the-proton-pass-for-windows-app-finally-launches-with-the-addition-of-an-offline-mode/" rel="external nofollow">Windows</a>, <a automate_uuid="af05d43c-cd2f-461d-ad2f-8081cef3cf50" href="https://www.neowin.net/news/proton-launches-proton-pass-on-macos-and-linux/" rel="external nofollow">macOS, and Linux</a>, the <a automate_uuid="53de9392-6e81-4d44-9a1c-45023dff7fa5" href="https://www.neowin.net/news/the-proton-pass-password-manager-adds-pass-monitor-for-better-identity-protection/" rel="external nofollow">Pass Monitor security dashboard</a>, <a automate_uuid="8d0ad0fd-7851-4c1a-9daf-1a034316bdb3" href="https://www.neowin.net/news/proton-pass-now-lets-you-securely-share-passwords-with-anyone/" rel="external nofollow">Secure Links</a> for sharing with non-users, encrypted file attachments, custom item types, and even a <a automate_uuid="0b7ae4c4-2232-48e1-af3e-683917e86787" href="https://www.neowin.net/news/proton-pass-gets-brand-spanking-new-cli-client-available-now-to-a-limited-subset-of-testers/" rel="external nofollow">command-line interface</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/proton-pass-is-getting-folders-an-ssh-agent-and-other-features-later-this-year/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 25 April 2026 at 7:50 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34713</guid><pubDate>Fri, 24 Apr 2026 21:50:37 +0000</pubDate></item><item><title>In a first, a ransomware family is confirmed to be quantum-safe</title><link>https://nsaneforums.com/news/security-privacy-news/in-a-first-a-ransomware-family-is-confirmed-to-be-quantum-safe-r34705/</link><description><![CDATA[<h3>
	Technically speaking, there’s no practical benefit to use PQC. So why is it being used?
</h3>

<p>
	A relatively new ransomware family is using a novel approach to hype the strength of the encryption used to scramble files—making, or at least claiming, that it is protected against attacks by quantum computers.
</p>

<p>
	 
</p>

<p>
	Kyber, as the ransomware is called, has been around since at least <a href="https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/kyber" rel="external nofollow">last September</a> and quickly <a href="https://cyber.netsecops.io/articles/new-kyber-ransomware-strain-discovered-with-advanced-encryption/?utm_me%E2%80%A6=" rel="external nofollow">attracted attention</a> for the claim that it used <a href="https://csrc.nist.gov/pubs/fips/203/final" rel="external nofollow">ML-KEM</a>, short for Module Lattice-based Key Encapsulation Mechanism and is a standard shepherded by the National Institute of Standards and Technology. The Kyber ransomware name comes from the alternate name for ML-KEM, which is also Kyber. For the rest of the article, Kyber refers to the ransomware; the algorithm is referred to as ML-KEM.
</p>

<h2>
	It’s all about marketing
</h2>

<p>
	ML-KEM is an asymmetric encryption method for exchanging keys. It involves problems based on lattices, a structure in mathematics that quantum computers have no advantage in solving over classic computing. ML-KEM is designed to replace Elliptic Curve and RSA cryptosystems, both of which are based on problems that quantum computers with sufficient strength can tackle.
</p>

<p>
	 
</p>

<p>
	On Tuesday, security firm Rapid7 <a href="https://www.rapid7.com/blog/post/tr-kyber-ransomware-double-trouble-windows-esxi-attacks-explained/" rel="external nofollow">said</a> it reverse-engineered Kyber and found that the Windows variant used ML-KEM1024, the highest strength version of the PQC (post-quantum cryptography) standard. Kyber was using ML-KEM to conceal the key used to encrypt victims’ data with AES-256, a symmetric cryptographic standard that is also quantum-proof. (As <a href="https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in-a-post-quantum-world/" rel="external nofollow">reported previously</a>, AES-128 would have sufficed in withstanding a quantum attack.) Brett Callow, a threat analyst at security firm Emsisoft, said it’s the first confirmed case of ransomware using PQC.
</p>

<p>
	 
</p>

<p>
	There is no practical benefit for Kyber developers to have chosen a PQC key-exchange algorithm. The Kyber ransom note gives victims one week to respond. Quantum computers capable of running <a href="link" rel="">Shor’s algorithm</a>—the series of mathematical equations that allow the breakage of RSA and ECC (elliptic curve cryptography)—are, at a minimum, three years away and likely much further.
</p>

<p>
	 
</p>

<p>
	A Kyber variant that targets systems running VMware,  meanwhile, claims to use ML-KEM as well. Rapid7 said its look under the hood revealed that, in fact, it uses RSA with 4096-bit keys, a strength that will take even longer for Shor’s algorithm to break. Anna Širokova, a Rapid7 senior security researcher and the author of Tuesday’s post, said the use or claimed use of ML-KEM is likely just a branding gimmick and that implementing it required relatively little work by Kyber developers.
</p>

<p>
	 
</p>

<p>
	In an email, Širokova wrote:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		<span style="font-weight: 400;">First, it’s marketing to the victim. “Post-quantum encryption” sounds a lot scarier than “we used AES,” especially to non-technical decision-makers who might be evaluating whether to pay. It’s a psychological trick. They’re not worried about someone breaking the encryption a decade from now. They want payment within 72 hours.</span>
	</p>

	<p>
		 
	</p>

	<p>
		<span style="font-weight: 400;">Second, implementation cost is low. Kyber1024 libraries (renamed to ML-KEM</span><span style="font-weight: 400;">)</span><span style="font-weight: 400;"> are available and well-documented. Ransomware doesn’t encrypt your files directly with Kyber1024. That would be slow. Instead, it:</span>
	</p>

	<p>
		 
	</p>

	<ol>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">Generates a random AES key</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">Encrypts your files with that AES key (fast)</span>
		</li>
		<li aria-level="1" style="font-weight: 400;">
			<span style="font-weight: 400;">Encrypts </span><i><span style="font-weight: 400;">that AES key</span></i><span style="font-weight: 400;"> with Kyber1024 (so only the attacker can decrypt it)</span>
		</li>
	</ol>

	<p>
		 
	</p>

	<p>
		<span style="font-weight: 400;">In Rust, there are already libraries that do Kyber1024. The developer just adds it to their dependencies and calls a function to wrap the key.</span>
	</p>
</blockquote>

<p>
	Despite the hype, Kyber suggests that PQC is attracting the attention of less technically inclined attorneys and executives deciding how to respond to ransom demands. Kyber developers are hoping the impression that the encryption has overwhelming strength will sway people to pay.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2026/04/now-even-ransomware-is-using-post-quantum-cryptography/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 24 April 2026 at 4:10 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34705</guid><pubDate>Fri, 24 Apr 2026 06:11:15 +0000</pubDate></item><item><title>Microsoft says Windows 11&#x2019;s built-in 'Defender' antivirus is "usually sufficient" for most PC users: "I haven't used a 3rd party antivirus since XP"</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-says-windows-11%E2%80%99s-built-in-defender-antivirus-is-usually-sufficient-for-most-pc-users-i-havent-used-a-3rd-party-antivirus-since-xp-r34684/</link><description><![CDATA[<h3>
	The company says Defender is enough for most users, provided default protections stay on, and updates are installed regularly.
</h3>

<p id="elk-fa1a4d7e-2d1e-4525-8bd6-2a44c415965a">
	In a world where bad actors are increasingly adopting sophisticated techniques to deploy malicious attacks, including general <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/artificial-intelligence" data-before-rewrite-redirect="https://www.windowscentral.com/tag/artificial-intelligence" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowscentral.com/artificial-intelligence" href="https://www.windowscentral.com/artificial-intelligence" rel="external nofollow">artificial intelligence</a> to unsuspecting users, it feels like a no-brainer to have some kind of antivirus installed on your device.
</p>

<p>
	 
</p>

<p>
	Having an antivirus installed helps protect you against malware, phishing attacks, and ransomware that can give hackers unauthorized access to sensitive data. Luckily, Microsoft ships Windows 11 with <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/how-to-get-started-with-microsoft-defender-antivirus-on-windows-11" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowscentral.com/software-apps/windows-11/how-to-get-started-with-microsoft-defender-antivirus-on-windows-11" href="https://www.windowscentral.com/software-apps/windows-11/how-to-get-started-with-microsoft-defender-antivirus-on-windows-11" rel="external nofollow">Microsoft Defender</a> as an in-box app to help curb such issues and provide users with real-time protection and advanced features designed to keep their system secure.
</p>

<p>
	 
</p>

<p>
	<a id="elk-seasonal" rel=""></a>
</p>

<p aria-hidden="true" id="elk-fa1a4d7e-2d1e-4525-8bd6-2a44c415965a-2">
	<em>“For many Windows 11 users, Microsoft Defender Antivirus covers everyday risk without requiring additional software,”</em> Microsoft indicated in <a data-analytics-id="inline-link" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.microsoft.com/en-us/windows/learning-center/best-antivirus-software-for-windows#wl" href="https://www.microsoft.com/en-us/windows/learning-center/best-antivirus-software-for-windows#wl" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">a Learning Center article </a>earlier this month (via <a data-analytics-id="inline-link" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowslatest.com/2026/04/21/microsoft-quietly-reveals-whether-you-need-a-third-party-antivirus-software-in-windows-11/" href="https://www.windowslatest.com/2026/04/21/microsoft-quietly-reveals-whether-you-need-a-third-party-antivirus-software-in-windows-11/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">Windows Latest</a>). This seems to have been fuelled by users going the extra mile to install third-party antivirus software on their devices to handle the same task.
</p>

<p>
	 
</p>

<p aria-hidden="true">
	Microsoft's response to skeptics questioning Defender's capabilities is simple and clear: <em>“Windows antivirus protection is usually sufficient when Windows 11 runs with default protections enabled, updates are installed regularly, and software downloads are deliberate.” </em>
</p>

<p>
	 
</p>

<p aria-hidden="true">
	However, the tech giant hasn't completely written off the value of third-party antivirus software, especially depending on how you use your Windows PC and the features you value.
</p>

<figure id="elk-b27ae615-44e7-489f-b97a-738e4b3df217">
	<blockquote class="QuoteNewsStyle">
		<p>
			The choice to add third‑party antivirus depends on how you use your PC and which features you value. You might consider extra security software if you manage multiple devices, share devices with family members, or want services like identity monitoring or parental controls.
		</p>

		<p>
			 
		</p>

		<p>
			<em><cite>Microsoft</cite></em>
		</p>
	</blockquote>
</figure>

<p id="elk-e13f36a1-f8fe-4319-945f-6b3b3f840b4e">
	Why not run multiple antivirus programs on your Windows PC, including Microsoft Defender? The company warned that it may cause system conflicts and stress your device's resources.
</p>

<p>
	 
</p>

<hr>
<p>
	 
</p>

<p id="elk-c5386f19-993b-4132-b3c1-0dae79db1cd7">
	Microsoft also warned users against over-reliance on third-party antivirus software, citing that <em>“each added tool increases background activity and complexity, so choose tools that match real needs.”</em> As expected, the company used the opportunity to toot its own horn, highlighting the benefits of using Microsoft Defender as your default antivirus in Windows 11, including anti-phishing and ransomware protection.
</p>

<p>
	 
</p>

<p>
	I did some brief groundwork to see what the community thinks about Microsoft Defender in Windows 11. In the<a data-analytics-id="inline-link" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.reddit.com/r/Windows11/comments/1ol2h6d/new_windows_11_laptop_needs_antivirus_or_not/" href="https://www.reddit.com/r/Windows11/comments/1ol2h6d/new_windows_11_laptop_needs_antivirus_or_not/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow"> r/Windows11 subreddit</a> on <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/reddit" data-hl-processed="none" data-mrf-recirculation="inline-link" data-url="https://www.windowscentral.com/tag/reddit" href="https://www.windowscentral.com/tag/reddit" rel="external nofollow">Reddit</a>, a user asked whether they'll need a third-party antivirus or if Microsoft Defender would suffice
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedid="embed4080687598" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://www.reddit.com/r/Windows11/comments/1ol2h6d/new_windows_11_laptop_needs_antivirus_or_not/?embed_host_url=https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-built-in-defender-antivirus-is-usually-sufficient-for-most-pc-users" style="overflow: hidden; height: 326px;"></iframe>
</div>

<p>
	 
</p>

<p id="elk-3d35bf23-d730-40c3-9c42-7fc18f4c7e6d">
	Everyone in the comment section pretty much said the same thing: Microsoft Defender is enough and works just fine. <em>"I haven't used a 3rd party antivirus since XP,"</em> a user indicated.<em> "Windows Defender is enough and maybe even too much," </em>another user added.
</p>

<p>
	 
</p>

<p>
	<em><strong>Do you use Microsoft Defender on Windows 11? Let me know in the comments.</strong></em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.windowscentral.com/microsoft/windows-11/microsoft-says-windows-11s-built-in-defender-antivirus-is-usually-sufficient-for-most-pc-users" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post. Feedback welcome.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 23 April 2026 at 7:35 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of March) 1,297</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a></span></strong>
</p>
]]></description><guid isPermaLink="false">34684</guid><pubDate>Wed, 22 Apr 2026 21:39:58 +0000</pubDate></item><item><title>Android malware NGate steals NFC data through HandyPay app</title><link>https://nsaneforums.com/news/security-privacy-news/android-malware-ngate-steals-nfc-data-through-handypay-app-r34677/</link><description><![CDATA[<p>
	<span style="font-size:14px;"><strong>A trojanized HandyPay application is used by threat actors to grab the NFC payment data of android users</strong></span>
</p>

<p>
	 
</p>

<p>
	A campaign in November 2025, which targeted Android users in Brazil, is still active and rising at an alarming rate. ESET researchers have<span> </span><a href="https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/" rel="external nofollow">discovered</a><span> </span>a new variant of the NGate malware family that uses a trojanized version of the HandyPay application to steal NFC payment data of Android users. Research suggests that the source code for the malware was written using a GenAI.
</p>

<p>
	 
</p>

<p>
	The threat actors are mainly targeting Android users in Brazil. This was found while analyzing the attackers' C&amp;C server. This is done with the trojanized app widely circulated through a fake website impersonating a Brazilian lottery, "Rio de Prêmios", as well as through a fake Google Play page. When asked about this to HandyPay, they confirmed that an internal investigation is ongoing on their side.
</p>

<p>
	 
</p>


	<a href="https://cdn.neowin.com/news/images/uploaded/2026/04/1776771952_codelog.webp" rel="external nofollow"><img alt="Code snippet of the Ngate malware" data-ratio="75.10" height="475" width="776" src="https://cdn.neowin.com/news/images/uploaded/2026/04/1776771952_codelog.webp" /></a>

	
		<p>
			Code snippet - Image via ESEST
		</p>

		<p>
			 
		</p>
	


<p>
	A massive use of GenAI is used to develop malware. As seen in the above code snippet, the malware logs contain emojis, which are generally seen in AI-generated texts. This suggests that LLMs were used to modify or generate the code, although there is no conclusive proof.
</p>

<p>
	 
</p>


	<img alt="1776772162_trojan_flow.webp" class="ipsImage" data-ratio="75.10" height="384" width="720" src="https://cdn.neowin.com/news/images/uploaded/2026/04/1776772162_trojan_flow.webp" />
	
		<p>
			Image via ESET
		</p>

		<p>
			 
		</p>
	


<p>
	The start of the attack is done through the lottery page, where the victim clicks on the 'Button to claim prize' and installs the trojanized HandyPay apk. Once installed, the apk behaves as the original application, which makes it difficult for the user to detect anything unusual. The user is then asked to enter the PIN of the card into the app and tap the card at the back of the smartphone with NFC enabled. While in the background, the malware collects the victim's payment information and card data and relays it to the hacker. With this done, the threat actor can use this relayed data to perform contactless transactions as well as withdraw cash from the ATM.
</p>

<p>
	 
</p>

<p>
	While explaining, ESET said, "The operator’s device is linked to an email address hardcoded within the malicious app, ensuring that all captured NFC traffic is routed exclusively to the attacker. We have observed two different attacker email addresses being used in the analyzed samples. On top of the standard batch of data that is transferred in the NFC relay, the victim’s payment card PIN is exfiltrated separately to a dedicated C&amp;C server over HTTP, not relying on HandyPay infrastructure. The C&amp;C endpoint for PIN harvesting also functions as the distribution server, centralizing both delivery and data-collection operations".
</p>

<p>
	 
</p>

<p>
	Over the growing use of NFC payments, experts warn to be wary of such attacks and install applications from official sources. The use of Generative AI also triggers the idea that a person without technical expertise is bound to hack into payment systems.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/android-malware-ngate-steals-nfc-data-through-handypay-app/" rel="external nofollow">Source</a>
</p>
]]></description><guid isPermaLink="false">34677</guid><pubDate>Wed, 22 Apr 2026 18:58:21 +0000</pubDate></item></channel></rss>
