AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure

 AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure
  • Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution
  • Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals
  • Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid

If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.

Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.

In their mission, they launched an experiment - to port a remote code execution (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.

Yes, but...

Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode.

It is indeed a worrying development, but one that comes with a huge “but”:

“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.

“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”

In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when Sandworm struck Poland’s electricity suppliers.



from Latest from TechRadar US in Computing News https://ift.tt/gotZx2c
via

'That's how you actually end a live service' — this developer just shut down a free-to-play game by releasing an offline version with no microtransactions for fans to keep playing

 'That's how you actually end a live service' — this developer just shut down a free-to-play game by releasing an offline version with no microtransactions for fans to keep playing
  • Free-to-play live service game Let it Die shut down earlier this week
  • It's not the end, though, as players will still be able to play the game in a new offline state
  • The new offline version costs just $19.99 / £16.99 / AU$28.50 and has all microtransactions removed

It feels like a live service game is shutting down every few weeks, and I'm no stranger to the crushing disappointment of learning that one of your favorite games is going offline.

Under the Radar

Under the Radar is our way of highlighting great games that might have passed you by. Through a regular mix of news stories and features, we'll cover great experiences that we feel haven't found the audience they deserve. Read the full series here.

Normally, the news means you lose access to the game for good — with all your progress, achievements, and in-game items vanishing along with it. Just look at Vampire: The Masquerade - Bloodhunt, Anthem, or Hawked: three offline titles that died in the last few weeks alone and are now completely inaccessible by official means.

Although the reasons for such shutdowns are often understandable, it still seems like a massive waste of resources, development time, and sometimes some genuinely good game mechanics or ideas.

With Let it Die, however, developer Grasshopper Manufacture is defiantly bucking that trend. The free-to-play game shut down earlier this week after nine whole years on the market, but that doesn't mean it's now unplayable.

The company put in the work to create an offline version, which you can buy on PC or PlayStation 4 for $19.99 / £16.99 / AU$28.50. You lose some of the original's offline features, but all microtransactions are removed so you can experience the full game without having to open your wallet more than once.

You can even bring over your progress from the online game if you played it before.

A positive example

If you're not familiar with Let it Die, it's a roguelike hack-and-slash with a challenging, almost soulslike combat loop that has you battling your way through a massive enemy-filled tower.

Players loved its wacky writing (with iconic characters like its skateboarding rendition of the Grim Reaper) when it first released back in 2016, but microtransactions were pretty pervasive. In short, it was designed to make you part with real money to keep reviving your characters when you died, which, given the high level of difficulty, was pretty often for most.

With these mechanics now removed, I'm already seeing long-time fans call this new release the definitive version.

"Great to see this game won't ever die due to its servers being shut down now," wrote one Steam reviewer. "Plus all the crappy monetization which held the game back a ton is gone."

Others praise the decision to keep the game alive in some form: "Shutdown the servers but made sure the game was still playable afterwards. That's how you actually end a live service."

Of course, the irony of a game called Let it Die carrying on forever is not lost. "Can't say the devs don't have a sense of humor," quipped one player.

It goes to show that the end of a live-service title doesn't have to screw over gamers, and I hope other developers take note of the positive reception.



from Latest from TechRadar US in Gaming News https://ift.tt/3wR7Jmb
via TECHNICAL SAFEER

Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices

 Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices
  • McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records
  • Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M
  • Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed

Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters extortion group.

McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”.

The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack.

Boston Scientific works on restoring systems

The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation.

Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems.

“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”

Boston Scientific is yet to name ShinyHunters as the perpetrators, and the group has not yet publicly claimed responsibility for the attack.

Via The Register



from Latest from TechRadar US in Computing News https://ift.tt/xgoa8TR
via

'It's been particularly bad since Blackwell': Nvidia's new GPU driver has another nasty bug — and gamers are rapidly losing patience

 'It's been particularly bad since Blackwell': Nvidia's new GPU driver has another nasty bug — and gamers are rapidly losing patience
  • Nvidia's latest graphics driver has a frustrating bug
  • Version 616.56 is causing distracting screen flickers and color corruption
  • A patch is coming, and there are potential workarounds — but gamers are getting fed up with the prevalence of bugs in GeForce drivers

Nvidia's latest graphics driver is causing chaos for some GeForce GPU owners in the form of a glitch that makes the screen flicker.

Wccftech spotted the bug with Nvidia's Game Ready Driver version 616.56, and as flagged by Renan Maniero on X, Team Green has said it's testing a fix for the issue (as revealed on the GeForce forums).

The screen is reportedly flickering white or black and exhibiting other brief flashes of color corruption, and this is happening in certain games (The Last of Us and Minecraft are mentioned, among others) or on the Windows desktop. It's also occurring in web browser sessions and while playing YouTube videos, based on Reddit reports — of which there are plenty.

There's no shortage of gamers losing their temper with Nvidia, too, and blasting Team Green for the quality of its graphics drivers. Many are venting with an observation that GeForce drivers just haven't been the same since the launch of the RTX 5000 series.

For example, this Redditor says: "It's been particularly bad since Blackwell [RTX 5000] release. Just on Blackwell alone, between the whole DisplayPort 2.1 not working with HDR, screen flickering, and black screens on the initial release, it's been a complete mess."

Another gamer complains: "It is pretty shocking seeing this from a trillionaire company on a stable build. Nothing about this driver is stable."

Yet another Redditor grumbles: "It's crazy how things are now. You used to be able to update each time or be one driver behind at worst. Now I'm half a year outdated and thinking I'll just leave it."

Analysis: more drivers, more problems? There are possible workarounds though

Nvidia GeForce RTX 2080 shown close-up in a motherboard

Even older GeForce graphics cards are affected here (Image credit: Future)

This seems like quite a widespread issue and one that affects modern Nvidia graphics cards all the way back to RTX 2000 models.

If you're getting frustrated by this bug — random screen flickering gets pretty old, pretty fast, if it's happening regularly — Maniero also shared an apparent potential workaround on X that you can try while waiting for the official fix.

Seemingly, this is a bug that mostly affects monitors in 8-bit mode, and if you switch to 10-bit color (assuming your display supports this), the problem may disappear. Maniero also suggests that you try turning on Windows Auto Color Management (ACM).

Other folks on Reddit have shared various possible remedies, including switching from DisplayPort to an HDMI connector instead, and disabling Multi-Plane Overlay (MPO) in Windows 11, as one Redditor suggested. Nvidia provides a Registry file for turning off MPO (and enabling it again), but as ever with anything in this area of Windows, proceed at your own risk. (Although this method should be much safer than trying to edit the Registry directly yourself).

Your other choice is simply to roll back driver 616.56 to an earlier version, and there's no shortage of gamers who've done exactly that and report that the problem vanishes.

Hopefully Nvidia's official flicker-begone patch will be coming soon enough in the form of a hotfix, because this is an unduly annoying gremlin in the GeForce works that needs to be sorted out promptly.



from Latest from TechRadar US in Computing News https://ift.tt/kIaSyWT
via

Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware

 Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware
  • Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts
  • Compromised routers act as operational platforms
  • Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach

Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers.

Once they compromise a router, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars.

For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of malware spoofing legitimate software.

Target behind the target

The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario:

“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.

Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.

Via BleepingComputer



from Latest from TechRadar US in Computing News https://ift.tt/SroJ1GQ
via

Sony is channeling Tubi with its new Live TV on PS5 free streaming platform — here are the 100 live channels and on-demand movies you can stream now

 Sony is channeling Tubi with its new Live TV on PS5 free streaming platform — here are the 100 live channels and on-demand movies you can stream now
  • Sony is launching a new free ad-supported service on PS5 consoles
  • Its 100 live channels cover a wide range of titles across film, TV, news, sports, and more
  • Live TV on PS5 is available to US users now, with availability for Canada and other regions to follow

Sony is dipping its toes back into free streaming channels with its new Live TV on PS5 platform — following platforms such as Tubi, Google TV Freeplay, and The Roku Channel.

The gaming and entertainment giant announced Live TV on PS5 yesterday (August 31), revealing that PS5 owners in the US can now access the service’s 100 ad-supported live channels and on-demand titles. Sony also has plans to expand Live TV on PS5 to Canada and additional regions, and will roll out the free service to Bravia TVs later this year.

For a new free streaming platform, Sony is already going big with its entertainment offerings. As far as its movie channels go, Live TV on PS5 has a slew of titles spanning action, horror, sci-fi, and more, all while housing popular anime titles from Crunchyroll.

The service also has a rich catalog of TV titles, including shows such as Community, The Shield, Hell’s Kitchen, The Walking Dead, Forensic Files, Unsolved Mysteries, Deal or No Deal USA, and Fear Factor.

Movies and shows aside, current affairs and news viewing is also available for free, offering programming from NBC News Now, Fox Weather, and LiveNOW from FOX. Additionally, you can also access channels including FOX Sports, NASCAR, NBC Sports Now, and UFC, so sports fans aren’t being left out of the experience.

Just like other platforms in our roster of best streaming services, Sony will keep Live TV on PS5 refreshed with new programming, titles, and channels to expose you to new content and keep you on your toes. Hopefully its library won’t remain stagnant and outdated, but it’s not as if Sony doesn’t know what it’s doing — it’s dipped its toes into the FAST channels waters before.

PlayStation Vue was a live TV service that allowed you to watch titles without the need for a cable box, before Sony axed it in 2020. It’s safe to say that PlayStation Vue was a widely admired service, and countless PS owners have been reminiscing about its nostalgia on Reddit following the announcement of Live TV on PS5 — however, whether the new platform will be a welcomed addition is debatable.

Comment
 from r/gaming

Sony’s decision to kill off physical games and shift to digital ownership is still under intense scrutiny, not to mention the uproar that came when Sony deleted 500 movies users paid for following a licensing conflict. So there’s still the burning question regarding ownership: if everything is digital, do users really own it? There’s also the question of how different Sony’s FAST streaming service is to existing platforms.

In the Reddit discussion mentioned earlier, some users flagged that a lot of the FAST channels available on Live TV on PS5 are strikingly similar to the ones already available on services such as Tubi and Pluto TV, as one user said it ‘sounds like the same channels as [my] Roku TV’. Similarly, another commenter wrote that Sony’s streaming platform looks ‘like a copy of Roku TV, where they only show reruns and older shows, or lesser known shows’.

The common denominator with the best free streaming services are the providers, as another user highlights in the thread, so running into the same types of programming across these platforms isn’t out of the ordinary. For users who use their PS5 consoles as their main media hub, it’s a solid free upgrade and it’s there if you want to use it. At the same time, you can already download Tubi and Pluto TV on PS5, so the competition is tough.



from Latest from TechRadar US in Gaming News https://ift.tt/g3PvBsz
via TECHNICAL SAFEER

New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

 New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
  • Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs
  • Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant
  • Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks

Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor.

Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack.

“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.

Look for lateral movement

Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.

It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network.

In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement.

“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”

Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:

“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”



from Latest from TechRadar US in Computing News https://ift.tt/8uLqkAd
via

TP-Link reveals 'world's first Wi-Fi 8 lineup' at IFA 2026 with Archer 9 Ultra router and Deco 8 Ultra mesh Wi-Fi system

 TP-Link reveals 'world's first Wi-Fi 8 lineup' at IFA 2026 with Archer 9 Ultra router and Deco 8 Ultra mesh Wi-Fi system
  • TP-Link has unveiled two new Wi-Fi 8 routers at IFA 2026
  • The Archer 9 Ultra is a traditional router with a smart design and coverage of up to 3,600 square feet
  • The Deco 8 Ultra is a mesh system, and a 3-pack is good for a home of up to 9,800 square feet

TP-Link has revealed the world's first Wi-Fi 8 routers at IFA 2026, with two models arriving in the form of a standard router and a mesh Wi-Fi offering.

These are the Archer 9 Ultra router and the Deco 8 Ultra, the latter being the mesh Wi-Fi system. Both are built around TP-Link's Wi-Fi 8 StabilityEngine.

With the Deco 8 Ultra, you're getting a tri-band (including 6GHz) Wi-Fi 8 mesh system offering a speed of 22Gbps (19Gbps in Europe). A 3-pack of these cylindrical routers can cover a home of up to 9,800 square feet, with support for 200+ devices.

The Archer 9 Ultra boasts a tri-band speed of 19Gbps and bristles with 18 antennas, delivering coverage of up to 3,600 square feet in your home (or 3,000 square feet in Europe).

TP-Link underlines three key benefits of these routers thanks to Wi-Fi 8. First, they are more reliable with a greater number of devices hooked up, and they also cope much better with interference. Finally, Wi-Fi 8 allows for a better wireless connection at the edge of the system's effective range.

Handling devices more reliably is facilitated by Dynamic Sub-band Operation (DSO) and Non-Primary Channel Access (NPCA) tech. The former ensures every connected device gets only the bandwidth it needs — so more is open for other usage — and NPCA opens a second channel if the main one gets too busy. Or as TP-Link puts it, "Every device gets its own fast lane."

New modulation technology in these routers helps to deal with interference from other devices or nearby networks (like your neighbor's Wi-Fi), and boosts performance at longer distances from the router.

There are also Enhanced Long Range (ELR) and Distributed Resource Units (DRU) features with these Wi-Fi routers, which further strengthen the wireless signal at the edge of its reach.

TP-Link notes, "ELR extends the router's usable range, while DRU concentrates a device's limited uplink power into a narrower band so it can be heard clearly from far away. Uploads, calls, and camera feeds hold where they used to stutter."

Both routers benefit from a smart and contemporary design, with a minimalist and streamlined look. TP-Link argues that it needs to make its hardware look good so it won't be hidden away in a cupboard or under a table.

Gary Chang, Lead Industrial Designer at TP-Link, commented, "We stopped building a piece of networking equipment and started designing for the home. When a router's design becomes something people want to display, it ends up exactly where it performs best."

Analysis: ready for the future of Wi-Fi

TP-Link Archer 9 Ultra router shown on a table next to a laptop

(Image credit: TP-Link)

Wi-Fi 8 doesn't deliver any speed boost over Wi-Fi 7, at least not in terms of raw performance — but it does aim to improve performance by delivering a stronger signal when you're further away from the router, and a more reliable connection overall. Part of that strategy is to better deal with interference from other wireless networks (or appliances in general), and as TP-Link observes, this is a big part of the puzzle here.

We don't yet have a release date (or price) for the Archer 9 Ultra or Deco 8 Ultra, but the expectation is that these routers will ship later this year. Of course, to get the benefit of a Wi-Fi 8 router, you'll need devices that support the new wireless standard, too — and they won't be here for a while yet.

Indeed, the Wi-Fi 8 standard itself is still a draft and not finalized, and the likes of smartphones and laptops won't arrive with Wi-Fi 8 support until next year (and there probably won't be very many of them, either, to begin with).

That said, your Wi-Fi 7 (or earlier) devices will still run just fine on a Wi-Fi 8 router, because as ever, the new standard is fully backwards compatible — you just won't get the benefits that Wi-Fi 8 phones and laptops will (when they arrive).

That said, some of the improved traffic management and interference reduction tech in these routers will still help with devices that don't support Wi-Fi 8. However, buying a Wi-Fi 8 router later this year when these TP-Link models (and others) emerge is more about future-proofing than anything else for now.



from Latest from TechRadar US in Computing News https://ift.tt/5a3Br4x
via

Asobo Games says it would 'love' to make a modern-day entry in the A Plague Tale series, since Naughty Dog's The Last of Us 'was a big inspiration'

 Asobo Games says it would 'love' to make a modern-day entry in the A Plague Tale series, since Naughty Dog's The Last of Us 'was a big inspiration'
  • Asobo Games says it's interested in making a new A Plague Tale game set in the modern day
  • The studio says it would be like The Last of Us, since Naughty Dog's game was a "big inspiration"
  • Actor Anna Demetriou says a modern-day spin-off would work well since the Macula is "fantastical"

Asobo Games has said it "would love" to make a new A Plague Tale game set in the modern day, since Naughty Dog's The Last of Us influenced the series.

In an interview with TechRadar Gaming at Gamescom ahead of the launch of the studio's latest game, Resonance: A Plague Tale Legacy, Valérian Robert (lead level designer), Carol Ann Bañuls (lead writer), and actor Anna Demetriou, who played the part of Resonance protagonist Sophia were asked about its next project and confirmed that a modern-day spin-off is something they're asked about frequently.

"Absolutely," Bañuls replied when asked if the setting would be a good pick for Asobo. "Definitely. Personally, I think so. I think it would be great."

Demetriou said, "It's one of the things a lot of people ask me about," with Bañuls adding, "It would be really Last of Us kind of."

Bañuls went on to say that, "Yeah, definitely, because it was a big inspiration. So yeah, if it's in modern days, it would be great."

In the A Plague Tale universe, the Prima Macula is an ancient curse that poisons the blood of certain families and is something that appears in every major A Plague Tale game, including Resonance: A Plague Tale Legacy. Demetriou thinks the Macula would work very well in a modern-day setting, because the plague is "fantastical."

"It would be amazing," Demetriou continued, "I would love that to fit into a modern-day setting. Yeah, it would be interesting to see what that would look like. I would love that."

Asobi Games hasn't announced its next project just yet, but A Plague Tale game set in a time gamers are familiar with sounds awesome. Now, fans can pick up Resonance: A Plague Tale Legacy, which is available today on PS5, Xbox Series X, Xbox Series S, and PC.



from Latest from TechRadar US in Gaming News https://ift.tt/XpmztPS
via TECHNICAL SAFEER

'Beyond ridiculous': if you're seeing Lake Ontario renamed as Lake America on Google Maps, here's why

 'Beyond ridiculous': if you're seeing Lake Ontario renamed as Lake America on Google Maps, here's why
  • Lake Ontario is now Lake America in the US via an executive order
  • Google Maps has updated its maps to reflect the change
  • Viewing the map from outside the US still shows the original name

Some 18 months on from the controversial renaming of the Gulf of Mexico, another edit has been made to Google Maps at the behest of US President Donald Trump: Lake Ontario, spread across the US-Canadian border, is now Lake America.

Or rather, it is if you're viewing Google Maps from inside the US (via Gizmodo) — the rest of the world will still see the Great Lake labeled as it has been since at least the 17th century. The name Ontario most likely comes from the Iroquoian word Kaniatarí:io or Oniatarí:io meaning "lake of shining waters" or "beautiful lake", as per Wikipedia.

The name change is the result of an executive order from the White House, as President Trump bickers with Canada over trade tariffs. In response, Canadian authorities have installed a large new sign at the lake (via the BBC), reading 'Lake Ontario. Now and Always'.

Reactions on Reddit are calling the switch "beyond ridiculous" and "braindead", though some commenters are pointing out that Google is obliged to follow the lead of the US Board on Geographic Names (part of the United States Geological Survey).

Google responds

For its part, Google has also chimed in to say that it has to follow "official government sources" when it comes to place names, saying that "these updates follow our long-standing policy for bodies of water with names that vary from country to country, and are starting to roll out now".

"People using Maps in the US will see 'Lake America', those in Canada will continue to see 'Lake Ontario', and those outside of the US and Canada will see both names," according to the official blog post from Google Maps on the matter.

However, not everyone is towing the line on this: New York State Governor Kathy Hochul took to social media to declare that "New York won't be calling it [Lake America]", so there are going to be some pockets of resistance regarding the change.

As yet the change hasn't rolled out on Apple Maps, but presumably it'll eventually have to comply with the official government, and start renaming Lake Ontario depending on where in the world you're viewing the map from.



from Latest from TechRadar US in Computing News https://ift.tt/Tei7P6r
via

Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks

 Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks
  • Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals
  • AI agents could install malware if they execute hallucinated or outdated documentation commands
  • Fixes: clean documentation and restrict AI agents from treating docs as executable instructions

Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through AI agents, new research has claimed.

An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.

Researchers have analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains they found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.

Claiming packages and domains

There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.

Now, for the purpose of the experiment, the researchers registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”.

This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register malware. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device.

Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said.

To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands.

Via Ars Technica



from Latest from TechRadar US in Computing News https://ift.tt/WTanNyB
via

Carhartt data breach exposed information from 12.9 million user accounts

 Carhartt data breach exposed information from 12.9 million user accounts
  • ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks
  • Data stolen from Databricks platform included names, emails, phone numbers, and addresses
  • Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption

Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.

The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach.

"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.

Compromising analytics platforms

It added that the demand was $3.3 million, which Carhartt turned down:

"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told the extortionists.

At the same time, security researcher Troy Hunt from HaveIBeenPwned? analyzed the leaked batch and concluded that it most likely came from Carhartt’s Databricks analytics platform.

Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains "millions of synthetic records that did not relate to real individuals and were excluded from the breach."

ShinyHunters is currently one of the most active threat actors. They started as a typical ransomware group but decided to abandon the encryption part and to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages.

After gaining a foothold, they target for SaaS solutions, through which they steal valuable information. They have claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.

Carhartt runs roughly 60 stores around the US, and employs some 3,000 people, bringing in an estimated $1.8 billion in annual revenue.

Via BleepingComputer



from Latest from TechRadar US in Computing News https://ift.tt/tI3nlxV
via

'No, you cannot do the game 100% without killing' — Rainbow Six Tactics game director confirms players can't do a complete no-kill playthrough since some missions require players to kill enemies that are out of range for non-lethal takedowns

 'No, you cannot do the game 100% without killing' — Rainbow Six Tactics game director confirms players can't do a complete no-kill playthrough since some missions require players to kill enemies that are out of range for non-lethal takedowns
  • Ubisoft confirms players can't complete Rainbow Six Tactics without killing any enemies
  • Game director Martial Potron says, "No, you cannot do the game 100% without killing"
  • Some missions require players to kill enemies; however, they're incentivized to do non-lethal takedowns in others for valuable intel

Rainbow Six Tactics game director Martial Potron has confirmed players won't be able to achieve a 100% non-lethal playthrough.

Ubisoft has recently revealed its new Rainbow Six Siege spin-off, Rainbow Six Tactics, a single-player turn-based tactics experience that puts players in the shoes of Six, the leader of the elite Rainbow squad.

Players can choose high-stakes assignments to strategize on the tactical battlefield with 15 Operators, all with unique abilities, specialized gadgets, and distinct skill trees.

The game will also offer distinct mission types, including Hostage Rescue, Bomb Disposal, and Target Elimination, offering a variety of ways to complete each one.

Some missions require players to take down targets non-lethally to collect important intel bonuses that will help the squad in future missions. But can players do a complete non-lethal playthrough?

According to Potron, who discussed the game at length in an interview with TechRadar Gaming at Gamescom, you can't, explaining that some missions will require players to kill enemies who are out of range for non-lethal takedowns.

"Can you?" the game director said. "I'm thinking about it. There is no incentive to kill, but can you? I think you can't."

He continued, "We don't have missions where we force you to kill anyone. Most of the time, in fact, it's valued to arrest people to subdue enemies. But we have a few missions when sometimes you cannot reach enemies."

Porton said the game features a Venice map bisected by a river, with enemies on one side, and so there is no way to take them out non-lethally, as you simply won't be able to reach them.

"No, you cannot do the game 100% without killing," he added, "but you are strongly incentivized, as much as possible, to arrest people without killing because you will be able to really get intel from them, and it's very valuable."

Rainbow Six Tactics launches in 2027 for PC, PS5, Xbox Series X, and Xbox Series S.



from Latest from TechRadar US in Gaming News https://ift.tt/unLiGxJ
via TECHNICAL SAFEER