OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT

 OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT
  • OpenAI says it has disrupted a social media influence campaign that is believed to be of Russian origin
  • What makes this campaign stand out is the underlying architecture, which features a "think tank" with highly questionable credibility
  • The objective of the campaign was to influence Western audiences into believing Russia was superior, and that Western countries were sacrificing their sovereignty

AI tools have once again been used for bad, rather than for good, and this time it has been as part of a campaign attributed to Russia that tried to discredit Western countries supportive of Ukraine.

The threat actors used ChatGPT accounts to promote the work of an “expert community” of academics known as the International Burke Institute (IBI). The site used stolen academic works attributed to the wrong authors in an attempt to appear legitimate while also hiding the true source of its academic ‘contributions’.

The IBI was registered to an address in Israel - with some evidence suggesting real individuals in Israel represented and promoted the page - but the main purpose of the misinformation campaign was to paint Russia in a favourable light compared to its Western adversaries.

International Burke Institute, or an institute run by international berks?

In its report on the campaign OpenAI points out that those behind the ChatGPT accounts used to promote the page took careful steps to hide their Russian origins. Many of the prompts included instructions to hide any linguistic clues that the operators used Russian language prompting.

One inclusion on the IBI website referred to Germany’s traffic light coalition as the “Svetofor coalition”. Svetofor is the word for ‘traffic light’ in numerous Slavic languages, including Russian, indicating that drafts were written in Slavic languages before being translated.

Some of the accounts were used to promote the IBI across X, LinkedIn, Facebook, Substack and Telegram with AI generated imagery and captions, with other accounts being used to automatically engage with comments by real users on Substack. The operators of the ChatGPT accounts regularly requested performance summaries of these pages in Russian, and used ChatGPT to generate matching profile pictures for some accounts.

Burke Sovereignty Index

One of the features of the IBI website is to advertise the ‘Burke Sovereignty Index’ - designed to measure how well a country performs compared to others across political, economic, technological, informational, cultural, cognitive and military factors.

The Index’s purpose is to make Western countries appear worse than Russia, OpenAI says. Having taken a look at the Index myself it's clear there is no consistency in measurement or comparison. For example, The Vatican City - which is less than half a square kilometer in size - sits above Spain in its average of scores. The Index also gave Russia the highest military score.

Questionable expert contributors

The website also includes a list of experts, whose affiliation to the IBI is not referenced. Some among them are pioneers in their fields of study, such as Francis Fukuyama and Noam Chomsky.

Others are former high-ranking members of the US government, such as Mike Pompeo and Joseph Nye. There are even listings for experts who passed away before the IBI was founded, such as Shlomo Avineri and Jiang Ping.

Much of the academic work cited on the IBI website is legitimate, but more often than not has been stolen from its actual author and misattributed to a different author to hide the work’s actual source, OpenAI said. This has been done to give the IBI website credibility and to make it appear authentic.

Impact of the IBI influence campaign

The overall impact of the IBI and its promotion using social media and ChatGPT is fairly limited, OpenAI noted. Some of the Telegram channels garnered followings between ten to twenty thousand showing a limited breakout to authentic audiences.

But the main thing to take away from this is the level of dedication placed behind the underlying infrastructure of the IBI. The site is designed to look authentic, uses authentic research (even if it is wrongly attributed), and presents itself as a collection of experts. To the layman, a cursory glance at the IBI website would give any of their social media presence a level of authenticity not seen in other social influence campaigns.



from Latest from TechRadar US in Computing News https://ift.tt/J6erIKf
via

Of course, this fake GTA VI ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached

 Of course, this fake GTA VI ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached
  • GTA VI leak hunters now face fake downloads designed to compromise their computers
  • The suspicious ISO reportedly disables Windows security tools after execution on affected systems
  • A tiny 50KB payload allegedly sits inside a gigantic 113GB file

Keen Grand Theft Auto VI fans searching for leaked copies now face another risk: a huge ISO file is reportedly circulating across torrent sites.

The file is said to measure 113GB, yet online testers claim almost all that space consists of empty data rather than genuine game assets.

Their analysis reportedly found a small malicious program hidden inside the file, making the download appear far more dangerous than it normally would.

The huge size made it feel genuine

The suspicious file reportedly began circulating on torrent sites after renewed interest in leaked GTA VI material and claims of a complete game build.

However, testers who examined the ISO reportedly found that it contains 99.99% empty zeroes, leaving only about 50KB of data identified as malicious code.

“I did some reverse engineering and confirmed that it is fully fake and full of viruses,” said @Aidas29506493, an online researcher on X.

The 113GB figure was created to make the file resemble a legitimate game release while concealing a much smaller payload, which could be ransomware.

Yet file size alone provides no evidence that an alleged copy contains authentic game assets or executable code from Rockstar.

The alleged code reportedly includes commands designed to weaken Windows Defender and interfere with other security tools on affected computers.

Such behaviour would allow the malware to operate with fewer protections after someone launches the downloaded file on Windows.

The analysis also reportedly found a PowerShell command that adds the system drive to Windows Defender's exclusion list for scanning.

Another command was said to terminate security software, although independent verification of those findings remains limited at this time.

Malware risk rises alongside GTA VI leak interest

The alleged ISO follows a series of GTA VI leak claims that have generated substantial interest across gaming communities online.

A leaker known as Cyberleek has reportedly shared gameplay material and the game's fictional Leonidas map, while demanding changes from Rockstar.

Take-Two Interactive has also sought information from Microsoft that could help identify users connected with three Discord servers reportedly linked to leaks.

Those developments have increased attention around unofficial GTA VI files, creating conditions that criminals can exploit with convincing fake downloads.

This situation also shows why unreleased game files can carry greater security risks than ordinary pirated software already available publicly.

Gamers downloading such files may expose passwords, personal files, browser data, or other information if malicious code gains access without warning.

Rockstar has scheduled the official release of Grand Theft Auto VI for November, giving players a legitimate alternative to unofficial copies elsewhere.

Until then, claims surrounding leaked builds and supposed ISOs should be treated cautiously because the files cannot be independently verified as genuine.

This case provides a strong warning, but further independent testing would be needed to establish every technical claim about the file itself.

Via Toms Hardware

Google logo on a black background next to text reading 'Click to follow TechRadar'



from Latest from TechRadar US in Computing News https://ift.tt/7Sirqt9
via

Everything announced at Gamescom Opening Night Live 2026 — from Heroes of Might and Magic 3 Remake to The Witcher 3 remastered and more

 Everything announced at Gamescom Opening Night Live 2026 — from Heroes of Might and Magic 3 Remake to The Witcher 3 remastered and more

Gamescom Opening Night Live 2026 has officially concluded, and the two-hour-long show was jam-packed with a deluge of game announcements and reveals.

From an official release date for the upcoming free-to-play open-world action game Ananta to our very first look at the highly anticipated The Witcher 3 Songs of the Past DLC, it offered a solid set of trailers — especially compared to some previous years.

If you weren't able to catch the show live, there's no need to worry about missing out. Here are the major announcements in the order that they happened to get you fully up to date.

Everything announced at Gamescom Opening Night Live 2026

  • Nodus Fall — a new co-operative action game from Genshin Impact maker Hoyoverse
  • Rainbow Six Tactics — new strategy spinoff launching in 2027
  • Gears of War: E-Day — our first look at the villain in new cinematic story trailer
  • Ananta — the free-to-play open world RPG is launching January 15, 2027
  • Silent Hill Townfall got a new story trailer showing some creepy enemies
  • Resonance: A Plague Tale Legacy got another gameplay trailer ahead of release this week
  • Sea of Remnants got a new gameplay trailer showing cute puppets and naval action
  • Crimson Desert Enhanced announced with new content
  • Tides of Annihilation trailer revealed new story details and gameplay
  • Lofsong — announced for console and PC
  • Megaman Dual Overdrive launches in 2027, and a crossover Pragmata skin is on the way
  • Rayman Legends Retold launches on October 1
  • PUBG Ded Net announced with a new gameplay trailer
  • Control Resonant got an awesome new gameplay trailer
  • The Blood of the Dawnwalker trailer revealed new story details and third-person action gameplay
  • Game of Thrones: War for Westeros got a new gameplay trailer showing Daenerys and Jon Snow — launches in early 2027
  • Dust Origins — a new isometric action game from Airship Syndicate
  • Exodus got a new gameplay trailer showcasing a new character, a talking octopus named Salt — out April 7, 2027
  • Warlock revealed as a new D&D game launching in 2027 for PC and console
  • 1001 Threads of Mizan revealed — new narrative game
  • Silver Palace: House of Greed got a new gameplay trailer
  • Monster Hunter Outlanders — mobile spinoff got a new trailer
  • Metro 2039 got a cinematic story trailer ahead of its February 2027 release
  • Hitman World of Assassination - The Herbalist ft. rap legend Snoop Dogg DLC launching for free on August 27
  • Aion 2 got a new trailer
  • Afterworld, a new strategy game from Paradox Interactive, announced
  • Petit Planet — life sim got an adorable new trailer

Gamescom 2026

A new Mega man skin is coming to Pragmata. (Image credit: Gamescom)
  • Mewgenics — comes to consoles on September 8
  • Alien Fireteam 2 got a new gameplay trailer
  • 1666: Amsterdam got a new trailer ahead of its early access release today
  • Showa American Story got a wacky new gameplay trailer, launching on PS5 and PC this year
  • Road Kings got a new trailer showing off plenty of trucking action
  • Stage Tour — upcoming Guitar-Hero-like music title got a brand new look showcasing setlists and ways to play ahead of December 10 launch
  • Crazy Taxi multiplayer reveal trailer
  • Turok Origins got a new cinematic trailer
  • Gravehounds, furry shooter, got a gameplay trailer ahead of 2026 launch
  • Lego Skylines — reveal trailer for bricky city builder game
  • Transport Fever 3 got a new trailer, launches September 26
  • Exterminauts announced
  • Path of Exile full 1.0 release on December 11, will be free-to-play
  • Heroes of Might and Magic 3 Remake revealed in cinematic trailer showing the reimagined strategy title

Gamescom 2026

Snoop Dogg is officially coming to the world of Hitman in upcoming DLC. (Image credit: Gamescom)
  • No Law announced for 2027
  • Project Zeta revealed as a new team-based MOBA
  • Cinder City announced with a new trailer, available wishlist now
  • Ontos announced with a creepy first-person trailer, launching 2027
  • Pony Island 2: Panda Circus launches April 27, 2027
  • Zoopunk gameplay reveal trailer shown
  • There are no Ghosts at the Grand got a new trailer and is launching December 2026
  • Roco Kingdom trailer confirmed closed beta test for October 27
  • The Defiant announced
  • Tarae the Unbound announced with a gameplay trailer
  • Like or Die — quirky social media battle royale announced
  • Final Fantasy 7 Revelation gets a new cinematic trailer

Gamescom Opening Night Live 2026 final announcement

  • The Witcher 3: Wild Hunt Remastered — announced as free upgrade with loads of new content
  • The Witcher 3: Wild Hunt Songs of the Past new cinematic footage shown

What did you think of this year's Opening Night Live show? Let us know in the comments or by voting in the poll below.



from Latest from TechRadar US in Gaming News https://ift.tt/bz7yGhY
via TECHNICAL SAFEER

The studio behind Crusader Kings and Hearts of Iron just revealed its first non-historical title in a decade — Afterworld is a new strategy game set in an original post-apocalyptic America

 The studio behind Crusader Kings and Hearts of Iron just revealed its first non-historical title in a decade — Afterworld is a new strategy game set in an original post-apocalyptic America
  • Paradox Interactive has revealed the upcoming grand strategy game Afterworld
  • It's set in a post-apocalyptic America that players can attempt to rebuild
  • It's intended to be the studio's most "easy to learn" and "approachable" title yet

Paradox Interactive has revealed Afterworld, an upcoming post-apocalyptic title that looks like the perfect cross between franchises like Fallout or Mad Max and the company's popular grand strategy games.

Created by Paradox Development Studio, the same team behind Crusader Kings 3 and Hearts of Iron 4, Afterworld takes place in an entirely original vision of post-apocalyptic North America filled with resources to exploit, territory to conquer, and rival groups to trade resources, ally with, or wage war against.

Initially, the game is all about building up some semblance of civilization by creating a home and choosing the laws and ethics of your tribe, with the scale gradually developing until you're going head-to-head with other emerging powers to decide the fate of the continent.

Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive

Different playable factions let you start your story as everything from apocalypse survivors that have just emerged from a hidden vault to fanatical zealots already familiar with the brutal new world.

“This is the first world we’ve gotten to build from scratch in a long time, and the first one we've had the pleasure of destroying before the game starts," explained game director Dan Lind.

"The old world is still out there in fragments, waiting to be found. What comes after it is entirely up to the players.”

Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive
Upcoming strategy game Afterworld.
Paradox Interactive

With its "small-scale" starting hours, Afterworld is intended to be the studio's most "easy to learn" and "approachable" title yet — which is good news given the complex systems of games like Hearts of Iron 4 can be incredibly tricky to pick up.

This doesn't mean that surviving is going to be easy, though: the world is full of dangerous old technology and unknown horrors. It's also home to the Ancients, immortal leaders that survived the apocalypse and now dominate the wasteland.

It also sounds like there is going to be a lot of depth, with the developer promising that the experience "as rich and complex" as fans have "come to expect" from its games.

Afterworld doesn't have a release date yet, but can wishlist it on Steam today.



from Latest from TechRadar US in Gaming News https://ift.tt/lpmFMfg
via TECHNICAL SAFEER

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

 Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds
  • Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pages
  • macOS users tricked into pasting Terminal commands, leading to AMOS infostealer infection
  • Campaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload worked

Cybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.

According to security researchers CATO CTRL, the crooks used Google Sites to create a fake version of the OpenAI Codex download site. To avoid being flagged by Google’s security systems and ultimately removed, the site itself contains no malicious code or download links, whatsoever. Instead, it hosts an iFrame that displays content hosted elsewhere.

Then, they advertised that site on the Google Ads network. Google is usually good at spotting and preventing malicious ads from running on its network, but sometimes threat actors steal legitimate accounts with good standing and use them to bypass automated scans and get the ads listed, while also spending other people’s money on the ad campaign.

Not ClickFix

The ads were displayed to users searching for “codex macos download”, at the very top of the page. Using both Google Sites and Google Ads is a deliberate attempt to appear legitimate and trustworthy since after all, many people trust whatever Google displays as the top result without double-checking or scrutinizing the result.

Those that do click will see a website that, by all accounts, looks like OpenAI’s download site for Codex, the company’s AI coding agent. The site has download buttons for both Windows and Mac, but only the latter works. The download and installation process was designed to look “advanced” - instead of getting an executable, the victims are told to paste a command in Terminal.

Cato’s researchers call this a ClickFix attack, but ClickFix usually displays a fake problem, before offering an equally fake solution. This looks more like another way to appear legitimate because after all, several AI agents are specifically designed to be installed and run from the macOS Terminal, including OpenAI’s Codex CLI.

The end goal of the campaign is to deploy AMOS, a known macOS infostealer capable of grabbing browser data, login credentials, cryptocurrency wallet information, and more.

Via SiliconANGLE



from Latest from TechRadar US in Computing News https://ift.tt/szkIS16
via

Amazon security engineer hacks PC accessories with Claude Opus to make them work better — Asus, Insta360 and Elgato products reverse engineered in hours for 'better control', but engineer admits this also 'scares me'

 Amazon security engineer hacks PC accessories with Claude Opus to make them work better — Asus, Insta360 and Elgato products reverse engineered in hours for 'better control', but engineer admits this also 'scares me'
  • A security engineer at Amazon hacked a bunch of peripherals using AI
  • Claude Opus did most of the legwork in applying modified firmware to a webcam, microphone and more
  • The relative ease with which AI allows this kind of modification points to a worrying future of peripherals being compromised on a grander scale

In another example of how AI could prove to be a threat to our devices, an Amazon security engineer has demonstrated how powerful Claude Opus is when it comes to reverse engineering PC peripherals.

Chaz Schlarp, who's a Senior Security Engineer at Amazon, wrote a blog post about experiments he conducted with a bunch of peripherals such as a webcam and a microphone.

He wanted to find out how easy it was to modify the firmware and pull off some useful tricks with these devices using AI, but clearly there's a darker side here — namely that the same access could be leveraged by a malicious actor to compromise your system via these gadgets.

Schlarp used Claude Opus 5 to mess around with the firmware for an Insta360 webcam, a Shure microphone, an Asus monitor, an Elgato video capture stick, and an Elgato mini-light (a compact device for lighting your streaming videos).

Schlarp explains: "My process was pretty much the same for each of these devices: grab a copy of the device's firmware and associated update tool from the manufacturer, throw it into my reverse engineering environment, tell Claude Opus 5 what my goals are, and let it churn."

One thing that became quite clear to the security engineer was that these devices lacked any decent firmware integrity protection to prevent modifying and applying a new firmware. Only the Elgato light had any defenses in this respect, and they were easy enough to circumvent.

Schlarp explains a trick with his Asus ROG Swift PG42UQ monitor to demonstrate the kind of useful utility that can be on offer with this kind of firmware modding. He found it was possible to remove an annoying pop-up warning that periodically tells the owner to run the 'pixel cleaning' process (although the engineer hasn't implemented the fix in the firmware yet). He also discovered a way to get DisplayWidget (a Windows utility) features running on his Linux system, with a shell script that can flick through certain bits of functionality like the hardware crosshair or FPS counter (which could be set up on hotkeys).

Most of what he did, though, was about proving how relatively easy it was to subvert the firmware using AI to do the heavy lifting, and, for example, disable the webcam's recording light (in the style of surveillance malware, so the user wouldn't know if the camera was secretly recording). He pulled off a similar feat with the microphone, so the mute LED could be on while the mic wasn't actually muted (this was leveraged via a 'full plaintext command shell').

Schlarp observed: "Peripherals have proven to be an ideal target for agentic RE [reverse engineering] — they're tiny computers attached to my computer, with a data connection to the host and usually a firmware update mechanism, so an agent has something to iterate against. The net outcome is better control and understanding of my machine."

Analysis: fast-tracked exploits?

Shure MV7 microphone

(Image credit: Shure)

The key point here is how easy Claude Opus made this task. 'Owning' all five of these peripherals boiled down to 13 hours of the AI beavering away under its own steam with just shy of 100 prompts from its human overseer.

Schlarp notes that: "Hardware is almost universally 'open' for tinkering at this point with just a couple hours of mostly hands-off machine-driven labor each, and I look forward to a near future where I can add features to my webcam firmware as easily as I can to software that runs on my Linux machine itself."

However, as mentioned, there's the dark side to all this, as Schlarp makes clear: "On the other hand, as a security professional, this scares me for several reasons. I would work from the operating assumption that any device attached to a computer could have had a malicious firmware implant performed, where previously that required significant per-model investment and was stereotyped as a 'state actor' kind of activity."

In other words, the main difficulty in executing these kinds of exploits is the labor and time required, which currently limits this to individually targeted attacks on more high value targets. However, now an AI agent is capable of doing the grunt work, it makes sense that these kinds of attacks could be far more prevalent as time rolls on.

That means all those peripherals attached to your PC could be used as ways to compromise you, or your system, in the future. Schlarp informs us that he's also managed to get a root shell on a commercial Dell display, adding that: "Obviously it was never best practice to let untrusted clients touch these things, but the speed and scale at which this can be executed makes the risk so much higher now."

There's a potentially bigger threat here, too: an AI-powered worm that automatically actions this kind of reverse engineering. Schlarp explains: "It's only a tiny leap to imagine that someone could make a self-replicating piece of malware that probes its environment, relaying reconnaissance back to a smart command-and-control that actively works to push itself into accessories and IoT devices and industrial equipment found adjacent to an infected target."

There are a lot of worries about where AI could be leading us, and far more dangerous security threats looming in the future (or indeed the present) is another unfortunate prospect to say the least.



from Latest from TechRadar US in Computing News https://ift.tt/PhNGrxa
via

Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet

 Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet
  • Hackers exploited trusted software updates to deliver malware directly into car head units
  • Kaspersky says this is the first campaign tailored specifically for vehicle head units
  • The malware can run silently without showing drivers any visible interface

Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.

A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.

According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.

Compromised update channels deliver malware straight into vehicles

Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.

The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.

Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.

Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.

Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.

The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.

Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.

The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.

BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.

Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.

According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.

Head units present a growing and largely unprotected attack surface

Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.

Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.

This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.

Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.

However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.

That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.

The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.

Google logo on a black background next to text reading 'Click to follow TechRadar'



from Latest from TechRadar US in Computing News https://ift.tt/Az1SUkY
via

New malware targets Microsoft Teams users by posing as your company's IT helpdesk

 New malware targets Microsoft Teams users by posing as your company's IT helpdesk
  • Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
  • Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
  • Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering

For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.

According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.

The malware itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.

This is not SickKids' first attack

BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.

The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device.

The full list of Indicators of Compromise (IoC) can be found on this link. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.

Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.

Via BleepingComputer



from Latest from TechRadar US in Computing News https://ift.tt/7Q5R1sC
via

Canadian SickKids hospital hit again by cyberattacks, more data stolen

 Canadian SickKids hospital hit again by cyberattacks, more data stolen
  • SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data
  • Clinical systems and patient records unaffected; patient care continued without disruption
  • Affected staff and applicants offered 24 months of free credit monitoring and identity protection

The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.

In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.

“Patient care has continued as usual”, it added.

This is not SickKids' first attack

After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed. It did not detail the nature of the exposed information, or how many people are affected.

Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.

“We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded. Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.

While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well.

At the time, LockBit was one of the most active and most dangerous ransomware operators. In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback. There are reports from late 2025 of LockBit 5.0 claims, including a purported attack on U.S Bank, but the news is yet to be confirmed.

Via The Record



from Latest from TechRadar US in Computing News https://ift.tt/pEHaDc2
via

Private equity giant Apollo confirms data breach saw personal info stolen

 Private equity giant Apollo confirms data breach saw personal info stolen
  • Apollo confirms July 2026 cyberattack via social engineering exposed PII in its cloud environment
  • Data included names, DOB, contact info, addresses, and Social Security numbers
  • Firm offers two years of identity protection; no evidence of dark web leaks yet

Apollo, one of the biggest private equity firms in the world, has confirmed it suffered a cyberattack which compromised some people’s personally identifiable information.

The company notified California’s Attorney General’s Office about the breach and shared a copy of the letter it is now sending out to affected individuals. It is impossible to discern from the letter if the victims are Apollo employees, customers, or someone else entirely, but the company did clearly explain what happened.

As per the letter, an unidentified threat actor tricked an Apollo employee into granting them access to the company’s cloud environment. The attackers used social engineering (usually phishing), which means the victim either tried logging in using a spoofed landing page, unknowingly installed an infostealer, or was convinced to grant the attackers access via remote monitoring and management software.

Was there really a hack?

The company spotted the attack a few days later, and after activating its safety protocols (notifying the police, enhancing its security protocols, and bringing in third-party forensic experts), launched an investigation which showed that the attackers accessed its cloud platform between July 6 and 10.

“During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number (SSN),” the company said. This means that financial data such as credit card or bank account information, was not compromised.

Still, cybercriminals can make use of this type of information, as is often the case in identity theft, business email compromise, and even wire fraud.

Apollo is now offering two years of free identity theft protection and monitoring for affected individuals through Cyberscout.

At press time, no threat actors claimed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web.

Via TechCrunch



from Latest from TechRadar US in Computing News https://ift.tt/VTFzds8
via

No driver, no problem — devs use Claude AI to craft native macOS tool for an 'obscure' Windows-only printer

 No driver, no problem — devs use Claude AI to craft native macOS tool for an 'obscure' Windows-only printer
  • India-based developer Kuber Mehta uses Claude Code to create a macOS driver for the HP Laser 1008a
  • Previously, only the official drivers for Windows and Linux were available for the relatively obscure 2023 laser printer
  • The AI-generated driver was created over a series of meticulous prompts, and is now available via GitHub

The days of avoiding hardware that is incompatible with your operating system could be over. A developer based in India has created a macOS driver for a largely unknown HP printer using Claude Code, the agentic command-line coding tool developed by Anthropic.

Released in 2023, the HP Laser 1008a was issued with drivers for Windows and Linux, but not macOS. By using AI to generate a driver for macOS, developer Kuber Mehta has demonstrated that incompatible hardware could soon be a thing of the past.

Mehta has shared the code on GitHub and has also posted about the process on social media, and also compiled a transcript of the exchange, which has been published online for reference.

HP’s Samsung printer

Describing the issue in the introduction to the transcript, Mehta explains that the HP Laser 1008a is a “rebadged Samsung, host-based printer that speaks a proprietary raster language (SPL3), and it has no macOS driver and no AirPrint.”

No SPL3 drivers have been published for macOS previously, so the process relied on a conversation with Claude Code and reference to the Windows and Linux drivers.

The GitHub intro adds that the HP Laser 1008a and siblings in the series (1003 and 1006 a/w) have another problem: “They do not speak PostScript or PCL.” Anyone familiar with the world of printer drivers will recognize the challenge faced by Mehta, which makes the use of Claude Code even more impressive.

Using Claude Code with the Opus 4.8 model, the driver was compiled in 30-40 prompts. This might have been even quicker had the AI not made various assertions that required correcting.

The process moved through “install the drivers” to establishing the print language by analysing the printer’s error pages, via direct contact with the device and “running HP's real rastertospl codec inside a Linux container to produce genuine SPL3, to a reboot-safe background daemon.”

From here, Mehta and Claude Code moved to the published, MIT-licensed installer, which patches the macOS open-source printer driver package SpliX, adding support for the SPL3 printers (by default, SpliX handles SPL2 and SPLc drivers).

Building from AI

While already a developer, Kuber Mehta admitted learning about macOS drivers from the process, perhaps an unforeseen benefit of using generative AI tools for coding.

The GitHub repo outlines some revisions that have been made to the initial release, which is now “a tiny native IOKit helper” that dispenses with Python, pyusb, and libusb and can be swiftly installed from the Terminal.



from Latest from TechRadar US in Computing News https://ift.tt/ZF7gr2m
via

'We're offering gamers not just two more headsets, but two different ways to experience their games' — Audio specialist beyerdynamic announces two new, affordable wireless headsets, the MMX 100 and MMX 130

 'We're offering gamers not just two more headsets, but two different ways to experience their games' — Audio specialist beyerdynamic announces two new, affordable wireless headsets, the MMX 100 and MMX 130
  • Beyerdynamic has announced the MMX 100 wireless and MMX 130 wireless
  • The MMX 100 wireless launches on September 1 for £89
  • The MMX 130 wireless arrives in October for £109

German audio specialist beyerdynamic has announced two new wireless headsets, the closed-back MMX 100 wireless and the open-back MMX 130 wireless.

Beyerdynamic's MMX gaming range expands with two new wireless headsets representing two styles of gaming: the closed-back MMX 100 wireless for players who want to minimize distracting ambient noise and focus on their game, or the MMX 130 wireless, which is ideal for gamers who prefer to experience the atmosphere, soundtracks, and ambient sounds in greater detail.

"With these two models, beyerdynamic is making its audio expertise accessible to an even wider gaming audience," the company said. "Rather than offering a plethora of unnecessary features and gimmicks, both headsets focus on the essentials: precise sound, high levels of comfort, flexible connectivity, and long-lasting quality."

The MX 100, with its velour ear pads and a lightweight 275-gram design, offers a closed-back design to reduce external noise, a detachable Meta Voice microphone for clear communication, and a replaceable battery that lasts over 80 hours.

It can also be connected to PCs, consoles, smartphones, and handheld devices via Bluetooth 6.0, the included low-latency USB dongle, or a cable.

As for the MMX 130, gamers can expect a wireless headset designed for audio enthusiasts, with an open-back design that balances "a natural, spacious soundstage" with external noise, whatever the user is listening to.

Sporting a titanium-coated 40 mm driver for precise sounds, the MMX 1300 is recommended for gamers who enjoy story-driven, open-world, role-playing games (RPGs), and simulation games.

"With the MMX 100 wireless and MMX 130 wireless, we're offering gamers not just two more headsets, but two different ways to experience their games," said Matthias Heilig, product marketing manager for gaming at beyerdynamic. "Those looking for focus and isolation will find it in the closed-back MMX 100 wireless. Those who want to experience gaming worlds as naturally and spatially as possible will find an exciting alternative in the open-back MMX 130 wireless."

The MMX 100 wireless will launch first on September 1 in Black and Arctic White for £89, while the MMX 130 wireless will follow in October, also in Black and Arctic White, for £109.

The MMX 100 wireless will also premiere at Gamescom 2026 and be available for public testing.



from Latest from TechRadar US in Gaming News https://ift.tt/eWCp0iL
via TECHNICAL SAFEER

Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams

 Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams
  • Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations
  • An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority
  • Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group

A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.

New research from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.

The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.

A dropcatch domain situation: A gambling business with a malware-enabling catch

Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes snags the occasional massive win for users who deploy such solutions.

This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.

Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.

The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.

Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.

More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures.

Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.

Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March.

They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.



from Latest from TechRadar US in Computing News https://ift.tt/F8MsKW9
via